lynx-buyback[.]xyz
“soluna vs SHARK - LynxHL Voting”
lynx-buyback.xyz — Inhalt nicht verfügbar. Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 5/93 (alphaMountain.ai, Gridinsoft, Seclookup, SOCRadar, URLQuery); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 70/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain lynx-buyback.xyz was registered on 21 February 2026 and is currently listed as offline. DNS resolution points to the IPv4 address 185.95.159.71, which belongs to AS209101 (Vendetta Inc.) and resolves to a hosting location in the Netherlands. The site presented a page titled “soluna vs SHARK – LynxHL Voting”, and its SSL certificate is identified as version R13. Intelligence indicates that the operation impersonates the Twitter brand and is classified as a crypto‑scam, consistent with the “Crypto Scam” label in the data set.
The domain appears on three independent security blocklists and has been actively blocked by the PhishDestroy, MetaMask, and SEAL filtering systems. VirusTotal analysis recorded five positive detections out of ninety‑three scanners, confirming that a subset of malware and phishing engines recognize the domain as malicious. The registration details, hosting ASN, and blocklist presence collectively suggest a purposeful campaign targeting cryptocurrency‑related transactions while leveraging the Twitter brand for credibility. However, the absence of a live HTTP response limits the ability to inspect the exact payload, user‑interaction flow, or any embedded malicious binaries.
Consequently, the full scope of the malicious content, including potential wallet‑drain techniques or credential‑harvesting forms, remains undetermined. Defensive teams should continue to enforce blocklist rules for lynx-buyback.xyz, monitor outbound connections to 185.95.159.71, and incorporate the domain into URL‑filtering policies. Additional sandboxing of any retrieved content, if the site reappears, would allow verification of the specific crypto‑draining mechanisms and support attribution efforts. Ongoing observation of related registrants and the AS209101 network is recommended to detect future iterations of the campaign.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt