# xn--ra7-62y.cc — SUSPICIOUS > PhishDestroy warns: xn--ra7-62y.cc may be a crypto drainer. 2/95 VirusTotal vendors flag it. Verify on PhishDestroy before interacting! ## Summary PhishDestroy has identified xn--ra7-62y.cc as a potential crypto drainer. This type of scam attempts to steal cryptocurrency from unsuspecting users by tricking them into signing malicious transactions or revealing their private keys. Users should exercise extreme caution and avoid interacting with this domain. This domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and first created on May 21, 2025. Currently, 2 out of 95 security vendors on VirusTotal flag this domain as malicious. The domain also appears on 1 security blocklist, specifically OISD. It resolves to IP address 172.67.162.108 and uses an SSL certificate issued by Let's Encrypt. If you have visited xn--ra7-62y.cc and suspect you may have been compromised, immediately revoke any approvals or permissions granted to the site for your crypto wallets. Transfer your cryptocurrency to a secure wallet and scan your devices for malware. It is also recommended to change your passwords and enable two-factor authentication on all your accounts. Report the incident to relevant authorities and cryptocurrency exchanges to help prevent others from falling victim to this scam. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-05-21 16:21:56 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 172.67.162.108 ## Detection Status - VirusTotal: 2 vendors flagged - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["OISD"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/ceae7261-9296-4cd4-b7dd-02e002b2a667 - PhishDestroy: https://phishdestroy.io/domain/xn--ra7-62y.cc/ - LLM endpoint: https://phishdestroy.io/domain/xn--ra7-62y.cc/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/xn--ra7-62y.cc/ Last updated: 2026-03-26