copperinu-cto[.]xyz
copperinu-cto.xyz — error del servidor (HTTP 502). Resumen de las pruebas: VirusTotal 2/93 (Fortinet, SOCRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, copperinu-cto.xyz, was registered on February 27, 2026, through NiceNIC International Group Co., Limited and is associated with generic phishing activity. Analysis indicates the domain was taken offline by July 25, 2026, though it previously resolved to 104.21.29.31, a Cloudflare IP (AS13335) located in the US. The domain uses Cloudflare nameservers (edna.ns.cloudflare.com, kevin.ns.cloudflare.com), a common infrastructure choice for phishing campaigns due to its ease of setup and privacy features. At the time of assessment, no SSL certificate was present, increasing the likelihood of interception or detection by security tools.
Detection data shows the domain was flagged by 2 of 93 security vendors on VirusTotal and appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL. The page title, 'Just a moment...', is consistent with Cloudflare's default interstitial page, suggesting the domain may have been caught in an early deployment phase or used as a redirector. Gridinsoft assigned a trust score of 0/100, reinforcing its classification as high-risk. Defenders should treat this domain as part of a broader phishing infrastructure.
While the exact target or scam type remains unconfirmed due to limited content analysis, the combination of Cloudflare hosting, recent registration, and blocklist presence warrants inclusion in threat intelligence feeds and web filtering rules. If the domain reactivates, monitor for changes in SSL status, page content, or additional detections. No brand-specific indicators were identified in the available data.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-19 02:55:31 UTC
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
PD-20260227-DAF557 Recipient: abuse@nicenic.net, abuse@gen.xyz, compliance@icann.org ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.