treasury-reserves[.]xyz
“Index of /”
treasury-reserves.xyz — Contenido no disponible (HTTP 502). Suplantación de marca: Backpack; Tipo de estafa: Investment Scam. Resumen de las pruebas: VirusTotal 14/94 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, Cluster25, CRDF); URLQuery 1 alert; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 95/100. Registrador: PDR.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of treasury-reserves.xyz shows a short‑lived infrastructure that was registered on March 22 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. The domain resolves to the Cloudflare edge address 172.67.159.241, which is associated with Cloudflare, Inc. in Canada. A Let’s Encrypt certificate was observed, confirming the use of a free TLS certificate. The domain was categorized as an investment‑type phishing campaign and has been taken offline at the time of reporting.
Detection data indicate that 14 of 94 security vendors on VirusTotal flagged the domain, and it appears on four external blocklists. It has been actively blocked by threat‑mitigation services including PhishDestroy, MetaMask, ScamSniffer, and SEAL. The nameservers listed are braden.ns.cloudflare.com and zainab.ns.cloudflare.com, both belonging to Cloudflare’s authoritative DNS set. No additional infrastructure such as command‑and‑control hosts or payload servers has been identified.
Given the observed indicators, defenders should add treasury‑reserves.xyz to domain blocklists, monitor for any re‑registration or similar domains using the same registrar, and enforce outbound filtering for connections to the associated Cloudflare IP range. Continuous re‑scanning of the domain’s SSL certificate and DNS records is recommended to detect potential resurrection. The limited lifecycle and the fact that the site is currently offline suggest a targeted, low‑volume phishing operation, but the presence of multiple vendor detections underscores a non‑trivial risk.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | treasury-reserves.xyz |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of treasury-reserves.xyz · checked Mar 18, 2026
Datos y informes externos
PD-20260318-45BB18 Recipient: abuse@publicdomainregistry.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.