# mavrykk.xyz — SUSPICIOUS > ALERT: mavrykk.xyz is a crypto drainer phishing site detected on September 21, 2025. It avoids VirusTotal detection (0/95 scans) but resolves to IP 63.176.8.218. ## Summary The domain mavrykk.xyz has been identified as hosting a cryptocurrency drainer phishing page designed to steal digital assets from unsuspecting users. When victims interact with the site, malicious scripts attempt to drain connected crypto wallets by tricking users into signing unauthorized transactions. This threat is particularly dangerous for cryptocurrency investors who may unknowingly authorize transactions while believing they are engaging in legitimate transactions. This domain was flagged by PhishDestroy’s automated systems using threat intelligence from Cosmotown Inc-registered infrastructure. mavrykk.xyz was created on September 21, 2025, and currently resolves to IP address 63.176.8.218. At the time of reporting, VirusTotal shows 0 out of 95 detection engines flagging it as malicious, indicating this phishing page remains under the radar of major antivirus platforms. The site also utilizes a legitimate Let’s Encrypt SSL certificate, which adds a false sense of security to potential victims. If you visited mavrykk.xyz, immediately disconnect your device from the internet to prevent ongoing data transmission. Check your crypto wallets and all online accounts accessed from this device for unauthorized transactions. Do not enter any credentials or approve wallet connections on this domain. Report the incident to your wallet provider and consider transferring remaining assets to a new, secure wallet if malicious activity is detected. Use PhishDestroy’s verification tool to confirm your future interactions with unknown domains and avoid similar threats. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-09-21 19:04:51 - Registrar: Cosmotown Inc - IP: 63.176.8.218 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/7498553a-c966-420a-a4e7-16a01180e21e - PhishDestroy: https://phishdestroy.io/domain/mavrykk.xyz/ - LLM endpoint: https://phishdestroy.io/domain/mavrykk.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/mavrykk.xyz/ Last updated: 2026-03-22