# e138a.xyz — MALICIOUS > e138a[.]xyz is a confirmed phishing domain operating in the crypto space. Our automated scanners detected wallet-draining capabilities on this site. This domain has been flagged and added to global threat intelligence feeds. ## Summary Threat Overview The domain e138a[.]xyz has been identified as a cryptocurrency phishing website. This malicious site targets Web3 users by mimicking legitimate crypto platforms to steal wallet credentials and digital assets. Attack Analysis Phishing sites in the cryptocurrency space commonly employ wallet-draining techniques, fake token approval requests, and seed phrase harvesting to steal digital assets from unsuspecting victims. Risk Indicators - Domain registered on xyz TLD - Contains cryptocurrency-related keywords - Domain length: 9 characters - Uses a TLD frequently associated with malicious domains - Contains numbers in the domain name, often seen in phishing - Vt Detected - Drainer Detected Protection Tips Always verify URLs before connecting your wallet. Use bookmarks for frequently visited crypto platforms. Enable transaction simulation tools to preview what you're signing. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Page title: welcome-BET365 ## Domain Intelligence - Registered: 2026-03-04 06:01:31 - Registrar: Gname.com Pte. Ltd. - Country: SG - IP: 45.196.247.25 - Nameservers: ns1.1111343.com ns1.dnsbm.com ns2.1111343.com ns2.dnsbm.com ns3.1111343.com ns4.1111343.com - SSL Issuer: R12 ## Detection Status - VirusTotal: 14 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "CRDF", "CyRadar", "DNS8", "ESET", "Emsisoft", "Fortinet", "Kaspersky", "LevelBlue", "Lionic", "Netcraft", "Sophos", "Webroot"] - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Screenshot: https://urlscan.io/screenshots/019ceee8-4546-7708-85f7-cc3329ed1466.png - Cloudflare Radar: https://radar.cloudflare.com/scan/8be9c0b0-39d5-4257-88cc-edf737a1b788 - PhishDestroy: https://phishdestroy.io/domain/e138a.xyz/ - LLM endpoint: https://phishdestroy.io/domain/e138a.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/e138a.xyz/ Last updated: 2026-03-16