xn--ve-6kca[.]xn--mppshbr-2fgcd9li3a70yha6062idaj[.]upkyberwallet[.]com
“upkyberwallet.com | 522: Connection timed out”
xn--ve-6kca.xn--mppshbr-2fgcd9li3a70yha6062idaj.upkyberwallet.com — No verificado. Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 6/91 (ChainPatrol, alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar); PhishDestroy score 71/100. Registrador: MAT BAO.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, observed on July 12, 2026, is classified as an active crypto drainer threat with a high-risk designation. Infrastructure analysis reveals the domain was registered on February 21, 2026, through MAT BAO CORPORATION and currently resolves to IP address 104.21.112.1, hosted on Cloudflare's network (AS13335) in the United States. The domain employs Cloudflare nameservers (kallie.ns.cloudflare.com and kyle.ns.cloudflare.com) and utilizes HTTP/3 protocol, with a Let's Encrypt SSL certificate issued under the E8 chain. The page title, 'upkyberwallet.com | 522: Connection timed out,' suggests either deliberate misconfiguration or a temporary outage, which is consistent with evasion tactics used by crypto drainer operations. A 403 HTTP status indicates restricted access, potentially limiting automated analysis. The domain appears on one security blocklist and is explicitly flagged as a crypto scam by at least one vendor. While two of 95 security vendors on VirusTotal have detected malicious indicators, the absence of broader detection does not reduce the assessed risk, as crypto drainers often employ short-lived infrastructure to evade detection. Defenders should treat this domain as hostile infrastructure. The use of Cloudflare does not imply legitimacy, as threat actors frequently abuse its services for anonymity and DDoS protection. Network-level blocking is recommended, particularly for organizations handling cryptocurrency transactions. Further monitoring is advised, as the domain remains active and may resume operations under a different configuration. The exact content of the site has not been analyzed, but the classification as a crypto drainer indicates it is likely designed to siphon digital assets from victims' wallets.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: upkyberwallet.com
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain upkyberwallet.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.