emaartoken[.]xyz
“Emaar Launching Coin (EMAAR) — Residents Airdrop”
emaartoken.xyz — Belum terverifikasi. Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 17/93 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); URLQuery 3 alerts; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: NiceNIC.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, emaartoken.xyz, is identified as a brand impersonation threat specifically targeting OKX, a cryptocurrency exchange platform. The site presents itself as an airdrop campaign titled 'Emaar Launching Coin (EMAAR) — Residents Airdrop,' falsely associating with the legitimate Emaar brand to deceive users into divulging sensitive credentials or transferring assets. The domain is currently offline, but prior activity indicates a deliberate attempt to exploit trust in established brands for financial fraud. Analysis of technical indicators reveals the domain was registered through NiceNIC International Group Co., Limited on February 21, 2026, an unusually future-dated creation that may suggest registry manipulation or data obfuscation. It resolves to IP address 172.67.166.128, hosted on AS13335 Cloudflare, Inc., a common infrastructure choice for threat actors due to its anonymization capabilities. The domain appears on one security blocklist and is flagged by 17 of 95 security vendors on VirusTotal, including detection as a phishing or fraudulent site. The SSL certificate, issued by Google Trust Services (WE1), provides a veneer of legitimacy while failing to mitigate the underlying malicious intent. Infrastructure analysis further confirms the domain's association with Cloudflare, which, while not inherently malicious, is frequently leveraged to obscure hosting origins and evade takedown efforts. The domain's current offline status suggests either a temporary suspension due to enforcement actions or a strategic withdrawal by the threat actor to avoid further detection. However, the infrastructure remains a latent risk, as the domain could be reactivated or repurposed for future campaigns. Organizations and individuals are advised to block the domain and its associated IP (172.67.166.128) at the network level, including DNS and firewall rules. Users who interacted with the domain should assume credential compromise and initiate password resets for any accounts accessed during the exposure window. Monitoring for related domains registered through NiceNIC or resolving to Cloudflare IPs may help preemptively identify similar threats. Given the elevated risk level, security teams should prioritize reviewing logs for connections to this domain or its IP, particularly in environments where cryptocurrency transactions are common.
Intelijen Keamanan Jaringan Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | emaartoken.xyz |
malicious | Sinkholed |
| Quad9 DNS | emaartoken.xyz |
malicious | Sinkholed |
| DNS4EU | emaartoken.xyz |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-17 03:00:17 UTC
Teknologi · 20 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comGoogle's bot-challenge service. On phishing sites, used to appear legitimate and filter out automated scanners.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
User-behavior analytics: heatmaps, session recordings, on-site surveys.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comPerformance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
PD-20260214-0805FE Recipient: abuse@nicenic.net Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive