xpm6[.]top
“$USDC Token Airdrop”
Resumen de las pruebas
This domain, xpm6.top, operates as a fraudulent airdrop scheme targeting cryptocurrency users. It presents itself as a legitimate USDC token distribution platform, using social engineering tactics to deceive visitors into connecting their digital wallets or disclosing private keys. The site specifically exploits the popularity of USDC, a widely recognized stablecoin, to lure victims with promises of free tokens. Once accessed, the domain likely deploys malicious scripts or phishing forms to harvest sensitive credentials, enabling unauthorized access to victims' cryptocurrency holdings. The threat primarily affects users engaged in decentralized finance (DeFi) or those actively seeking airdrop opportunities, with financial loss as the immediate consequence. Analysis indicates the domain was registered on March 5, 2026, through NiceNIC International Group Co., Limited, a registrar frequently associated with high-risk domains. At the time of assessment, the domain resolved to the IP address 188.114.96.3 and was flagged by 6 out of 95 security vendors on VirusTotal. Additionally, it appeared on three distinct security blocklists, further corroborating its malicious nature. The domain's trust score of 0/100 from Gridinsoft underscores its lack of legitimacy. Infrastructure analysis reveals the domain was taken offline, though similar threats often re-emerge under different names or IP addresses. If you visited xpm6.top or interacted with its content, immediate action is required to mitigate potential damage. First, disconnect any wallets or devices that were connected to the site and revoke all active sessions or permissions granted to unknown applications. Scan the affected device using updated security tools to detect and remove any malware or unauthorized scripts. Monitor all linked accounts, including cryptocurrency wallets and exchange platforms, for unauthorized transactions. If credentials were entered, transfer assets to a new, secure wallet and update passwords for all associated accounts. Report the incident to relevant financial platforms and consider filing a complaint with cybersecurity authorities to aid in tracking and disrupting the threat actor's infrastructure.
Instantánea de evidencia enviada
- Enviado
- Registros del libro
- 1
- ID del caso
PD-20260305-1FCE26- Título de la página capturada
- $USDC Token Airdrop
- Artefacto PDF
- Evidencia en PDF
Texto completo de la evidencia
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
8 fuentes externas supervisadas Sin coincidencias
Evidencia del resultado almacenada
Resultado y atribución del retiro
- Resultado
unknown- Disponibilidad
unreachable- Causa
origin_unreachable- Mecanismo
http_5xx- Confianza
- 20%
- Primera observación
- Última observación
Indisponibilidad estimada
Tiempo hasta la indisponibilidad: 0 hSHA-256 de la evidencia c5c1885602ee
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Estado del dominio
Accesible → Inaccesible
-
VirusTotal
2 → 6
-
Disponibilidad
Primer valor almacenado: DNS inactivo
f93a11f87e4d -
Disponibilidad
DNS inactivo → Desconocido
c96d0527c34c -
Disponibilidad
Desconocido → DNS inactivo
a7d4abe36b44 -
Disponibilidad
DNS inactivo → Retenido
16a48e833237 -
Disponibilidad
Retenido → DNS inactivo
f52d526b76a1 -
Disponibilidad
DNS inactivo → Desconocido
42e6d911907f -
Disponibilidad
Desconocido → Retenido
3a6846983aed
Mostrar todo (9)
-
Disponibilidad
Retenido → Desconocido
83096a577799 -
Disponibilidad
Desconocido → DNS inactivo
6dfe9145995c -
Disponibilidad
DNS inactivo → Retenido
e3cec95e91c7 -
Disponibilidad
Retenido → DNS inactivo
641ed81dc4d5 -
Disponibilidad
DNS inactivo → Desconocido
65f06e97788e -
Disponibilidad
Desconocido → DNS inactivo
d0b7046e8c2f -
Disponibilidad
DNS inactivo → Retenido
7bb1ef57bfe8 -
Disponibilidad
Retenido → DNS inactivo
ca9ed662b468 -
Disponibilidad
DNS inactivo → Desconocido
c5c1885602ee
Reportes de la comunidad
Reportado por 1 miembro de la comunidad; visto por primera vez el 05/03/2026
- Reportes almacenados
- 1
- URL únicas reportadas
- 1
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of xpm6.top · checked Jun 26, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.