labtradelive[.]xyz
“Account Suspended”
labtradelive.xyz — No verificado. Tipo de estafa: Account Takeover. Resumen de las pruebas: VirusTotal 4/95 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet); Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain labtradelive.xyz was registered on 26 October 2025 and is presently taken offline, displaying the HTTP page title "Account Suspended." Infrastructure analysis shows the domain resolves to the IPv4 address 195.26.87.207, which is allocated to AS43641 SOLLUTIUM EU Sp z.o.o. in the Netherlands. The authoritative name servers are ns1-ams.v-sys.org and ns2-ams.v-sys.org, and the registration was processed through NiceNIC International Group Co., Limited. No TLS certificate is presented for the host, indicating that any future service would be delivered over plain HTTP.
The domain has been listed on two security blocklists and is actively blocked by PhishDestroy and ScamSniffer, confirming that it has been identified as a malicious resource. VirusTotal scans reveal that four of ninety‑five anti‑malware engines flagged the domain, providing additional independent confirmation of its suspicious nature. The threat classification in the intelligence set is an "Account Takeover" scam, suggesting that the operator intends to lure victims into revealing credentials for the purpose of unauthorized account access. While the current offline status reduces immediate exposure, the infrastructure—particularly the dedicated IP address and persistent nameserver configuration—indicates that the actor could revive the site or spin up additional domains using the same hosting environment.
Defenders should therefore add labtradelive.xyz to internal deny lists, block traffic to 195.26.87.207 at the network perimeter, and monitor for any re‑registration or re‑activation of the domain. Email gateway filters and web proxies should be updated to reference the known blocklists (PhishDestroy, ScamSniffer) to prevent delivery of any future phishing messages that reference this host.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-12 03:08:49 UTC
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.