avely[.]xyz
“Google Chrome-webbrowseren”
The domain avely.xyz presented a page titled "Google Chrome-webbrowseren" while impersonating the Facebook brand as a social media scam. This site posed a threat by masquerading as a legitimate browser interface to deceive users into providing social media credentials or performing unauthorized actions, leveraging a trusted brand name to lower suspicion.
Technical evidence shows the site was flagged by 7 out of 95 VirusTotal vendors and detected by five security platforms: alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker, and Gridinsoft. It appeared on three blocklists. The domain is registered with Namecheap, hosted on IP 2a00:1450:4001:804::2004 (DE) under AS15169 Google LLC, and uses nameservers ernest.ns.cloudflare.com and naomi.ns.cloudflare.com. No creation date or SSL data was provided in the available data.
The site is currently DOWN/OFFLINE. GridinSoft trust rating is 0/100, and the DOM risk score is 70, indicating a high likelihood of malicious activity. Users should avoid any interaction with this domain or similar impersonation attempts.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | avely.xyz |
malicious | Sinkholed |
| DNS4EU | avely.xyz |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Abuse Report History · 4 stored reports over 43 days · click to expand
-
Report #1 Mar 16, 2026 · 23:29 UTCPhishing Abuse Report: avely[.]xyzabuse@namecheap.com
-
Report #2 ICANN CC 881h still active Apr 22, 2026 · 20:16 UTCESCALATION #2 (881h active): Phishing - avely[.]xyzabuse@namecheap.com abuse@centralnic.com compliance@icann.org
-
Report #3 ICANN CC 974h still active Apr 26, 2026 · 17:11 UTCESCALATION #3 (974h active): Phishing - avely[.]xyzabuse@namecheap.com abuse@centralnic.com compliance@icann.org
-
Report #4 ICANN CC 1023h still active Apr 28, 2026 · 18:03 UTCESCALATION #4 (1023h active): Phishing - avely[.]xyzabuse@namecheap.com abuse@centralnic.com compliance@icann.org
VirusTotal Analysis
Evidence & External Reports
PD-1773703788-avely.xyz Recipient: abuse@namecheap.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive