gnx676[.]it
Forensic brief
PhishDestroy identifies gnx676.it as a high-risk generic phishing domain impersonating SaxoTrader, posing serious danger to users by attempting to steal sensitive information. This threat is critical due to its active status and deceptive tactics. The domain was registered recently on February 21, 2026, and resolves to IP 188.114.97.3. It appears on three security blocklists and is flagged by 14 of 95 security vendors on VirusTotal, confirming its malicious intent. Users should avoid visiting gnx676.it and refrain from providing any personal or financial data. Reporting this domain to cybersecurity teams and using up-to-date threat detection tools will help mitigate risks associated with this active phishing threat.
Threat response pipeline
VirusTotal
Forensic Evidence CollectionEvidence capture
Domain Intelligence
Technical details
Public blocklist status
VirusTotal consensus
Aggregated detection across 14 security vendors.
Evidence & external reports
Were you affected by this site?
Were You Affected?
Report to your local authorities
Email template — registrar abuse
abuse@
Case: PD-
Embed this report
About this report
About this report: gnx676.it
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 14 security vendors on VirusTotal and 1 public blocklists.
The site displays a page titled “SaxoTrader”.
gnx676.it has been flagged by 12 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.