xrpblack26[.]com
“Even geduld...”
Résumé des preuves
The domain xrpblack26.com was registered on 21 February 2026 through REALTIME REGISTER B.V. and is served by the Cloudflare nameservers andronicus.ns.cloudflare.com and lina.ns.cloudflare.com. DNS resolution points to the Cloudflare‑owned address 104.21.29.159, which belongs to ASN 13335 located in the United States. No TLS certificate is presented for the host, indicating that HTTPS is not configured. The site’s HTML title is recorded as “Even geduld…”, and the Gridinsoft trust score is 0 out of 100, reflecting a very low reputation. VirusTotal reports that four of ninety‑three scanned scanners flagged the domain, confirming the presence of malicious indicators.
The domain appears in a single external blocklist and has been referenced in one AlienVault OTX pulse, demonstrating limited but existing community detection. PhishDestroy has taken the domain offline and listed it as blocked. Current online status is reported as offline. Analysis of the available evidence confirms that the domain is being used in a crypto‑related phishing campaign, as indicated by the classified scam type “Crypto Scam”. The lack of an SSL certificate, the low trust score, and the presence on multiple security feeds suggest an opportunistic infrastructure that relies on Cloudflare’s CDN to obscure origin.
Because the site is already taken down, direct probing of payloads is not possible; therefore the precise phishing page content remains uncertain beyond the recorded title. Defenders should continue to enforce DNS‑based blocking of 104.21.29.159 and add xrpblack26.com to local deny lists. Monitoring for re‑registration or rapid domain‑generation similar to the observed pattern is advisable, as is periodic re‑query of VirusTotal and OTX for any new detections. The registrar information provides a potential avenue for takedown requests should the domain reappear.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 13/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse forensique
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif