xrp-give[.]cc
“1 new message”
xrp-give.cc — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : XRP; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 92/100. Bureau d’enregistrement: CNOBIN INFORMATION TEC….
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of xrp-give.cc as of July 23, 2026 indicates that the domain is actively leveraged for brand impersonation targeting the cryptocurrency XRP. The domain was registered on 7 November 2025 through CNOBIN INFORMATION TECHNOLOGY LIMITED and resolves to the IP address 188.114.96.3, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. DNS resolution uses Cloudflare’s authoritative nameservers david.ns.cloudflare.com and hera.ns.cloudflare.com, suggesting the infrastructure is hosted behind Cloudflare’s CDN and WAF services. No TLS certificate is presented for the domain, meaning HTTPS connections are not available, which is consistent with a low‑trust configuration. The Gridinsoft trust score of 0 out of 100 further confirms the site’s malicious reputation.
Multiple detection mechanisms have flagged the domain. PhishDestroy has listed it as blocked, and it appears on at least one public security blocklist. VirusTotal reports that 14 of 95 scanned security vendors identified the domain as malicious, reinforcing the suspicion of phishing activity. The page title returned by HTTP requests is “1 new message,” which does not provide any legitimate context and may be used to entice victims. The current operational status is reported as offline, indicating that the site may have been taken down or is temporarily inaccessible, but the underlying infrastructure remains observable.
Given the evidence, defenders should continue to block DNS resolution for xrp-give.cc at the network perimeter and add the associated IP address 188.114.96.3 to any deny lists, keeping in mind that the IP belongs to a shared Cloudflare range and may host other unrelated services. Monitoring of the domain’s registration renewal and any re‑appearance of active web content is advised. Organizations that hold XRP assets should educate users about unsolicited messages claiming to originate from XRP‑related services and reinforce the use of official channels only.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse forensique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif