xalurxojup[.]cyou
“Nowy projekt o nazwie "RocketBitPro" został uruchomiony. Oferuje on każdemu mieszkańcowi Polski moż…”
xalurxojup.cyou — Contenu indisponible (HTTP 502). Résumé des preuves: VirusTotal 20/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); PhishDestroy score 95/100. Bureau d’enregistrement: Namecheap.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain is flagged for hosting a targeted financial fraud operation under the guise of a cryptocurrency investment opportunity named RocketBitPro. Analysis indicates the threat type is a crypto asset drainer combined with credential theft, specifically designed to exploit Polish-speaking users by promising unrealistic returns of up to 90,000 PLN monthly. The scheme employs psychological manipulation through high-pressure claims of limited-time offers and fabricated success stories to coerce victims into transferring funds or disclosing wallet credentials. Infrastructure analysis reveals multiple high-risk indicators. The domain xalurxojup.cyou was registered on January 8, 2026, through Namecheap, exhibiting an anomalous future creation date that suggests domain spoofing or registry manipulation. It resolves to IP address 172.67.204.89, hosted on Cloudflare's network (AS13335), which is frequently leveraged by threat actors to obfuscate backend infrastructure. The domain appears on one security blocklist and is flagged by 20 out of 95 security vendors on VirusTotal, with detection labels including 'phishing,' 'fraudulent investment,' and 'crypto drainer.' The SSL certificate is classified as WE1, indicating a low-trust or potentially automated issuance process. Additional evidence includes its current offline status and prior blocking by PhishDestroy, a specialized anti-phishing system. Mitigation requires a multi-layered approach tailored to crypto asset protection. Users should immediately cease all interactions with the domain and any associated communication channels, including email or social media links referencing RocketBitPro. Financial institutions and crypto exchanges should monitor for transactions linked to the domain or IP 172.67.204.89, particularly those involving Polish users or PLN conversions. Organizations should update endpoint protection rules to block the domain, IP, and any derived indicators of compromise (IoCs), such as the page title fragment or SSL certificate thumbprint. Victims are advised to revoke access to any connected wallets, rotate credentials for all financial accounts, and report the incident to relevant cybercrime units, including local law enforcement and crypto fraud reporting platforms. Proactive measures include deploying DNS-based filtering to prevent resolution of the domain and educating users about the hallmarks of fraudulent investment schemes, such as guaranteed returns and urgency-driven calls to action.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ZONE SHORTDOT · PREUVES PUBLIQUES
.cyou
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif