xeno-executor.lol
“Xeno | The Best Key-Less Executor”
Analysis of xeno-executor.lol as of August 06, 2026 shows that the domain is currently active and associated with a generic phishing campaign.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
Analysis of xeno-executor.lol as of August 06, 2026 shows that the domain is currently active and associated with a generic phishing campaign. VirusTotal reports that 16 out of 91 scanned security vendors classify the domain as malicious, indicating a moderate consensus among detection engines. The domain is listed on a security blocklist and has been explicitly blocked by the PhishDestroy filtering service, providing additional confirmation of its abusive nature.
DNS resolution points to the IPv4 address 216.198.79.1; no further hosting attribution such as ASN or geographic location is supplied in the available intelligence. No public SSL/TLS certificate data, HTTP status codes, or page title information have been disclosed, leaving those vectors unverified. Safe Browsing status, Open Threat Exchange (OTX) references, and registrar details are also absent from the current dataset, which limits the depth of the infrastructure profile.
Given the confirmed detections and blocklist presence, defenders should treat traffic to and from xeno-executor.lol as hostile. Recommended actions include adding the domain to DNS and proxy deny lists, enforcing outbound filtering for the associated IP address, and monitoring for any related indicators of compromise in network logs. Continuous re‑evaluation is advised as additional telemetry, such as SSL certificates or page content, becomes available.
Threat Response Pipeline
Public Blocklist Status
Blocklist coverage
11 monitored external feeds · stored snapshot Sep 9, 2026
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 4 identified
Three.js is a cross-browser JavaScript library and application programming interface used to create and display animated 3D computer graphics in a web browser using WebGL.
threejs.org 100% confidenceVercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of xeno-executor.lol · checked Aug 6, 2026
Technologies
4 high-confidence technologies identified
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive