canna272i7uai6h5ctkrrfttwv2naulak37gctk22t6erohxegtu46yd[.]xyz
Forensic brief
PhishDestroy identifies a newly active generic phishing site hosted at canna272i7uai6h5ctkrrfttwv2naulak37gctk22t6erohxegtu46yd.xyz, flagged for elevated risk and confirmed as a crypto drainer kit designed to harvest private keys and seed phrases. The domain uses no brand impersonation, relying purely on URL novelty and the appeal of cannabis-related branding to attract victims into connecting wallets and signing malicious transactions. At the time of discovery, the domain resolves to IP 188.114.97.3 via a Let’s Encrypt SSL certificate, indicating active HTTPS deployment to appear legitimate. This domain was registered on May 11, 2026, through NameSilo, LLC, giving it only weeks of operational history, which is typical for disposable drainer infrastructure. VirusTotal analysis returned a detection score of 1 out of 95 security vendors, highlighting its evasiveness against mainstream scanning tools. The domain remains unlisted on Google Safe Browsing (GSB) and shows zero appearance on major blocklists at the time of analysis, allowing it to circulate unchecked in crypto communities. These technical indicators suggest a recently deployed, low-signature threat with high potential for rapid victim acquisition before detection systems catch up. As of the latest scan, the domain remains active and classified as elevated risk. PhishDestroy continues to monitor and block this URL via seed eef135. All cryptocurrency users are advised to verify any .xyz links related to token airdrops or wallet connections using PhishDestroy’s real-time verification tool. The remaining risk remains elevated due to low vendor detection and short domain age, making proactive verification essential to prevent wallet compromise.
Threat response pipeline
Cloudflare Radar
Forensic Evidence Collectionabuse@gen.xyz with forensic evidence (metadata, screenshots, PDF).Evidence capture
Domain Intelligence
NameSilo, LLC
Technical details
Public blocklist status
Technologies
Technologies · 3 identified
VirusTotal consensus
Aggregated detection across 95 security vendors.
Site performance
Site performance analysis
Google PageSpeed Insights — mobile audit of canna272i7uai6h5ctkrrfttwv2naulak37gctk22t6erohxegtu46yd.xyz
Evidence & external reports
Were you affected by this site?
Were You Affected?
Report to your local authorities
Email template — registrar abuse
abuse@namesilo.com
Registrar: NameSilo, LLC Case: PD-PD-20260516-93E537
Embed this report
About this report
About this report: canna272i7uai6h5ctkrrfttwv2naulak37gctk22t6erohxegtu46yd.xyz
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal and 1 public blocklists.
The site displays a page titled “CannaExpress Access Queue”.
canna272i7uai6h5ctkrrfttwv2naulak37gctk22t6erohxegtu46yd.xyz has been flagged by 0 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.