xyuvrot[.]net
“СОСАЛ?”
ملخص الأدلة
PhishDestroy has identified the domain xyuvrot.net as a brand impersonation threat specifically targeting Coinbase users. This domain was designed to mimic the legitimate Coinbase platform, likely aiming to steal login credentials, financial information, or cryptocurrency assets. The page title observed was 'СОСАЛ?', which is a suspicious and potentially misleading string that does not match any legitimate Coinbase content. The presence of a drainer kit could not be confirmed from available data, but the domain's structure and purpose strongly suggest credential harvesting or financial fraud.
Technical indicators for xyuvrot.net paint a clear picture of its malicious nature. VirusTotal flagged the domain with a score of 4 out of 95 security vendors, indicating that multiple independent security engines have identified it as harmful. The domain was registered through Web Commerce Communications Limited dba WebNic.cc, a registrar sometimes associated with lower-quality or suspicious domains. Its IP address, 104.21.37.145, is linked to Cloudflare, which can be used to obscure the true hosting location. The domain was created on July 06, 2025, making it very recent at the time of analysis, and it appears on 2 security blocklists. The SSL certificate was issued by WE1, which is not a widely trusted certificate authority, further raising concerns. Google Safe Browsing (GSB) status was not explicitly provided but given the blocklist presence, it is likely flagged or suspicious.
As of the latest check, xyuvrot.net is offline, which is a positive development. This suggests that either the hosting provider or registrar has taken action to disable the domain, or the threat actor has taken it down voluntarily. However, users should remain vigilant as similar domains may reappear under different names or IP addresses. PhishDestroy recommends that anyone who may have interacted with this domain change their Coinbase passwords immediately, enable two-factor authentication, and monitor their accounts for unauthorized activity. Avoid clicking on links from unsolicited emails or messages claiming to be from Coinbase, and always verify the URL before entering sensitive information. The risk level remains elevated due to the targeted nature of this phishing campaign and the potential for financial loss.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب