app-synthetix[.]xyz
app-synthetix.xyz — No verificado. Suplantación de marca: Synthetix; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Forcepoint ThreatSeeker, Gridinsoft); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Registrador: Dynadot.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, app-synthetix.xyz, is actively flagged as a high-risk brand impersonation targeting Synthetix, a known decentralized finance platform. Registered on April 14, 2026, through Dynadot LLC, the domain resolves to IP address 172.67.184.58, hosted under Cloudflare, Inc. in Canada. Infrastructure analysis reveals Cloudflare nameservers (alexa.ns.cloudflare.com and randall.ns.cloudflare.com) and an SSL certificate issued by Google Trust Services (WE1), which are consistent with tactics used to obscure hosting origins and evade detection. The domain is currently blocked by three security blocklists, including PhishDestroy, MetaMask, and SEAL, and appears in one AlienVault OTX threat intelligence pulse. Gridinsoft assigns a trust score of 0/100, further indicating malicious intent. While the HTTP status returns a 403 error, the domain remains operational, suggesting potential intermittent availability or cloaking techniques to avoid automated scans. Defenders should note that the domain is explicitly categorized as an impersonation scam, though the exact content or functionality of the site has not been analyzed. Three of 94 security vendors on VirusTotal have flagged the domain, providing additional corroboration of its malicious nature. The combination of brand impersonation, low trust scores, and active blocklisting warrants immediate inclusion in threat intelligence feeds and network-level blocking. No evidence suggests compromise of legitimate Synthetix infrastructure, but the domain’s creation date and Cloudflare hosting align with patterns observed in recent phishing campaigns targeting cryptocurrency platforms. Organizations should monitor for related domains registered through Dynadot or resolving to the same IP range, as this may indicate a broader campaign.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | app-synthetix.xyz |
malicious | Sinkholed |
| DNS4EU | app-synthetix.xyz |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.