lynx-buyback[.]xyz
“soluna vs SHARK - LynxHL Voting”
lynx-buyback.xyz — Contenido no disponible (HTTP 502). Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 5/93 (alphaMountain.ai, Gridinsoft, Seclookup, SOCRadar, URLQuery); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 70/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain lynx-buyback.xyz was registered on 21 February 2026 and is currently listed as offline. DNS resolution points to the IPv4 address 185.95.159.71, which belongs to AS209101 (Vendetta Inc.) and resolves to a hosting location in the Netherlands. The site presented a page titled “soluna vs SHARK – LynxHL Voting”, and its SSL certificate is identified as version R13. Intelligence indicates that the operation impersonates the Twitter brand and is classified as a crypto‑scam, consistent with the “Crypto Scam” label in the data set.
The domain appears on three independent security blocklists and has been actively blocked by the PhishDestroy, MetaMask, and SEAL filtering systems. VirusTotal analysis recorded five positive detections out of ninety‑three scanners, confirming that a subset of malware and phishing engines recognize the domain as malicious. The registration details, hosting ASN, and blocklist presence collectively suggest a purposeful campaign targeting cryptocurrency‑related transactions while leveraging the Twitter brand for credibility. However, the absence of a live HTTP response limits the ability to inspect the exact payload, user‑interaction flow, or any embedded malicious binaries.
Consequently, the full scope of the malicious content, including potential wallet‑drain techniques or credential‑harvesting forms, remains undetermined. Defensive teams should continue to enforce blocklist rules for lynx-buyback.xyz, monitor outbound connections to 185.95.159.71, and incorporate the domain into URL‑filtering policies. Additional sandboxing of any retrieved content, if the site reappears, would allow verification of the specific crypto‑draining mechanisms and support attribution efforts. Ongoing observation of related registrants and the AS209101 network is recommended to detect future iterations of the campaign.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.