VirusTotal
8 / 91
“Modulares Raum- und Kommunikationssystem | CONNECT X”
PhishDestroy first observed connect-x.info on Oct 3, 2026. The hostname uses “connect,” a pattern consistent with a wallet-connection lure; no target brand is confirmed from stored content. The captured page title is “Modulares Raum- und Kommunikationssystem | CONNECT X”. Current evidence score: 95/100 (critical).
Positive findings are stored from 4 sources: VirusTotal, MetaMask, SEAL, and URLQuery. VirusTotal recorded 8 detections among 91 engines: alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker, G-Data, Gridinsoft, Kaspersky, URLQuery on Oct 3, 2026 at 17:11 UTC. MetaMask and SEAL listed the hostname in the separate external-blocklist snapshot on Oct 3, 2026 at 14:20 UTC. URLQuery recorded 2 detections; no observation timestamp was retained. Additional recorded evidence: AlienVault OTX listed 4 community pulse references (not vendor detections) on Oct 3, 2026 at 17:11 UTC. URLScan captured the page on Oct 3, 2026 at 16:42 UTC.
The collector marked the hostname reachable on Oct 3, 2026 at 16:42 UTC, but did not retain the HTTP response code. Latest classified outcome: unknown; cause probe inconclusive on Oct 3, 2026 at 14:42 UTC. Registration records for the domain list RegistryGate GmbH as the registrar and Sep 30, 2026 as the creation date. Registration preceded first observation by 3 days. At collection time, the hostname resolved to 212.25.26.173. The stored server header is nginx. The evidence archive retains 3 visual captures from PhishDestroy and URLScan.
The content indicators and 4 positive source findings support the current phishing classification.
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
ns2.interway.chns3.interway.chslash.iway.chLocation describes the IP network.
Google PageSpeed Insights — mobile performance audit of connect-x.info · checked Oct 3, 2026
212.25.26.173. 8 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive