# xa90p.net — SUSPICIOUS > xa90p.net is a crypto drainer impersonating a login portal. 0/95 VirusTotal detections reported so far. Verify on PhishDestroy to stay safe. ## Summary PhishDestroy identifies xa90p.net as an active generic phishing domain operating as a crypto drainer kit, designed to harvest wallet credentials or initiate unauthorized transfers. While no specific brand was targeted, the domain mimics legitimate login interfaces to deceive users into exposing sensitive information. The threat relies on social engineering rather than exploiting a particular platform’s vulnerabilities. This domain was flagged on March 16, 2026, resolving to IP 104.21.83.254 via Internet Domain Service BS Corp. As of the latest scan, xa90p.net shows 0 detections out of 95 engines on VirusTotal, has not been classified by Google Safe Browsing, and remains unlisted on major blocklists. The SSL certificate issued by Let's Encrypt may help it evade scrutiny by providing a false sense of legitimacy. The domain remains active with an 'under_investigation' risk status. Users are advised to block access to 104.21.83.254 and monitor connections to xa90p.net until further assessment. Remaining risk is moderate due to low detection coverage and potential for rapid takedown evasion. Organizations should include this IOC in their threat intelligence feeds and warn employees about unsolicited links. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-16 12:33:08 - Registrar: Internet Domain Service BS Corp. - IP: 104.21.83.254 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/0333032e-58bb-4892-a9e7-4e7540671b64 - PhishDestroy: https://phishdestroy.io/domain/xa90p.net/ - LLM endpoint: https://phishdestroy.io/domain/xa90p.net/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/xa90p.net/ Last updated: 2026-03-21