geniuscrypto[.]one2xcart[.]top
“Crypto Genius ™ - Die offizielle App-Website 2023 [AKTUALISIERT]”
geniuscrypto.one2xcart.top — Contenido no disponible. Suplantación de marca: Google; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 15/95 (BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker); PhishDestroy score 95/100. Registrador: NameSilo.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, geniuscrypto.one2xcart.top, was observed hosting a brand‑impersonation page that claims to be associated with Google. The site’s HTML title reads “Crypto Genius ™ - Die offizielle App-Website 2023 [AKTUALISIERT]”, which does not reference Google directly but the intelligence feed tags the domain as impersonating Google. The domain was registered on 9 January 2025 through NameSilo, LLC and is served from the IP address 95.211.36.86, which belongs to LeaseWeb Netherlands B.V. (ASN 60781) located in the Netherlands. No TLS certificate is presented, indicating the site was reachable only over HTTP.
The domain resolves via Cloudflare’s authoritative nameservers dana.ns.cloudflare.com and wells.ns.cloudflare.com. VirusTotal analysis shows that 15 of 95 security scanners flagged the domain as malicious, and Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the malicious assessment. The domain is currently listed on a single external blocklist and has been taken down by the PhishDestroy takedown service. Defenders should add the host 95.211.36.86 to network‑level deny lists, block DNS resolution for geniuscrypto.one2xcart.top, and monitor for any future re‑registration attempts.
Because the site lacks SSL, any attempted connections will be clear‑text and can be intercepted for additional forensic capture if needed. Continuous watch of the registrar NameSilo for new registrations containing the “geniuscrypto” label is recommended. Updating URL filtering rules to match the exact domain string will prevent accidental exposure. The limited detection footprint—only one blocklist entry and a modest VirusTotal detection count—suggests the campaign may be in an early stage or operating on a low‑volume basis, so rapid response is advisable to contain potential brand‑impersonation abuse.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: one2xcart.top
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain one2xcart.top behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.