xsec[.]keplindomi[.]workers[.]dev
“Pegasus - Next-Generation Data Infrastructure”
साक्ष्य सारांश
The domain xsec.keplindomi.workers.dev is listed as an active generic phishing site with a specific focus on cryptocurrency drainage. The domain was registered on May 01 2026 through Cloudflare, Inc. and resolves to the IP address 188.114.97.3, which is hosted in Canada by Cloudflare’s network. HTTP requests return a 200 status code, and the site presents a TLS certificate issued by Let’s Encrypt (E8). Technical profiling shows the front‑end is built with Three.js and Tailwind CSS, and assets are served from cdnjs. The server enforces HTTP Strict Transport Security and negotiates HTTP/3 connections, indicating modern configuration. No custom nameserver records were identified, and the Gridinsoft trust score is 0 out of 100, reflecting a high‑risk assessment. The visible page title, “Pegasus – Next‑Generation Data Infrastructure,” is unrelated to the underlying activity and is likely used to lure victims. Intelligence classifies the operation as a “Crypto Drainer” scam, suggesting the site attempts to trick users into transferring cryptocurrency to addresses controlled by the adversary. The domain appears on one security blocklist and is already blocked by PhishDestroy, though VirusTotal currently shows zero detections. Defenders should add 188.114.97.3 and xsec.keplindomi.workers.dev to network deny lists and enable DNS sink‑holing for the domain. Monitoring of outbound traffic for attempted crypto‑wallet connections to unknown addresses is advised. Continuous re‑evaluation is required, as the threat actor may modify the payload or shift hosting while retaining the same domain fingerprint.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
तकनीकें
6 उच्च-विश्वसनीयता वाली तकनीकें पहचानी गईं
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of xsec.keplindomi.workers.dev · checked May 1, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।