Skip to security report
Domain security and threat intelligence
capony.xyz favicon

capony.xyz

Threat verdict Critical 100/100 evidence score
Availability Cloaked · reachable Reachability observed through cloaking checks
VirusTotal detections: 12/91 Stored blocklist matches: 1 Scam type: Crypto Drainer Last known active
Jun 13, 2026
Actions API
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 12. Public blocklists reporting a match: 1. Exercise extreme caution — do not enter credentials or personal information.

Evidence Summary

CRITICAL
Score
100/100

The domain capony.xyz was registered through Go Daddy, LLC on May 15 2026. It first appeared on two public security blocklists and is currently listed by PhishDestroy and ScamSniffer. The registration date places the domain well within the current operational window for the reported campaign.

Infrastructure analysis shows capony.xyz resolves to the IPv4 address 13.248.213.45, which is hosted in Canada and associated with an AWS Global Accelerator endpoint. The site presents a valid TLS certificate issued by GoDaddy.com under the GoDaddy TLS Intermediate CA DV - R1v1 chain, and HTTP requests receive a 200 OK response. Gridinsoft assigns a trust score of 14 out of 100, indicating a very low reputation.

Threat intelligence classifies the domain as a high‑risk crypto drainer. Eight out of ninety‑five VirusTotal security vendors have flagged the domain, reinforcing the suspicion of malicious activity. The high risk level and active status align with the observed pattern of crypto‑related credential harvesting and fund diversion.

Open questions remain regarding the exact payload delivered by the site, the command‑and‑control infrastructure, and whether additional sub‑domains share the same IP. No public page content or landing‑page analysis has been released, so the specific techniques used to lure victims are not yet documented.

Defenders should immediately block DNS resolution for capony.xyz and any sub‑domains, enforce outbound filtering to the IP 13.248.213.45, and monitor TLS handshakes for the GoDaddy certificate chain. Continuous re‑scanning with VirusTotal and inclusion in internal blocklists are recommended to mitigate potential crypto‑drain attacks.

VirusTotal
VirusTotal
12 det.
Gridinsoft
14/100
TLS Certificate
GoDaddy.com / GoDaddy TLS Intermediate CA DV - R1v1
Age
4 mo
Observed status
Cloaked · reachable 200
PhishDestroy
DestroyList
Listed
Data coverage VirusTotal 12 / 91 OTX no community references TLS valid certificate, 79d WHOIS 4 mo old Screenshot not captured Gridinsoft 14/100

Threat Response Pipeline

Discovery
Checks
Reports
Availability
6/8

Public Blocklist Status

Stored detection

Cloaking alert

Cloaking type
status_split
Cloaking score
2/6

Domain Intelligence

Domain
Server / ASN AS16509 Amazon.com, Inc.
IP Reputation abuse score 1/100 12 reports Phishing checked Aug 26, 2026
Registrar Go Daddy
IP Address 13.248.213.45 CA
GeoCA Montreal, CA
NetworkAS16509 · AWS Global Accelerator (GLOBAL)
RegistrationCreated May 28, 2026 (111d) Expires May 15, 2027
Cloaking Cloaking Detected Status split · score 2/6
alive_content: raw=ok; http=200; via=https_proxy
checked Sep 16, 2026
HTTP Status200
Technical detailsDNS, SSL SANs, timestamps
First DetectedJun 13, 2026
Nameserversns30.domaincontrol.com
TLS Fingerprint
TLS Observationvalid from May 21, 2026scanned Jun 27, 2026
ICANN OVERSIGHT

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

12 / 91 security vendors flagged this domain
View on VT
Last analyzed First positive detection Previous stored snapshot: 13 detections
alphaMountain.ai
BitDefender
CyRadar
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
Lionic
SOCRadar
Sophos
Webroot

Community reports

Reported by 1 community member, first seen May 28, 2026

Stored reports
1
Unique reported URLs
1
Accepted1

Evidence & External Reports

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/capony.xyz"
  title="PhishDestroy threat report for capony.xyz"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>