Lompat ke laporan keamanan
⚠️
Domain ini telah ditandai sebagai berbahaya
Daftar blokir publik yang melaporkan kecocokan: 2. Berhati-hatilah — jangan memasukkan kredensial atau informasi pribadi.
Keamanan domain dan intelijen ancaman

tokensautofixss[.]xyz

“Hyperliquid l Airdrop”

Putusan ancaman Kritis 70/100 skor bukti
Ketersediaan Terselubung · dapat dijangkau Reachability diamati melalui pemeriksaan penyelubungan
Daftar blokir yang disimpan cocok: 2 Jenis penipuan: Fake Airdrop Terakhir diketahui aktif
11/05/2026 1 Report Sent CDN
Ringkasan laporan

tokensautofixss.xyz — Terselubung · dapat dijangkau (HTTP 502). Jenis penipuan: Fake Airdrop. Ringkasan bukti: VirusTotal 0 detections (engine total unavailable); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 70/100. Registrar: OwnRegistrar.

Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.

Ringkasan bukti
KRITIS
Ref
C6ADE952
Skor
70/100

PhishDestroy identifies tokensautofixss.xyz as an active brand impersonation site masquerading as OKX, a major cryptocurrency exchange. The domain leverages homoglyphs and misleading keywords ('tokens', 'autofix') to deceive users into entering credentials or cryptocurrency wallet details. This tactic is consistent with credential theft operations observed in crypto drainer campaigns, where threat actors harvest login credentials to facilitate unauthorized withdrawals or account takeovers. While no specific drainer kit has been publicly associated with this domain yet, its registration and naming strategy align with known modus operandi of financially motivated cybercriminals targeting OKX users. Organizations and individuals must treat this domain with extreme caution and avoid interaction. tokensautofixss.xyz exhibits several red flags across multiple threat intelligence sources. VirusTotal reports 0/95 detections as of current scanning, indicating that major antivirus engines have not yet flagged this domain. Registered through OwnRegistrar, Inc., the domain resolved to IP address 172.67.203.57 at the time of discovery. The domain was created on May 08, 2026, making it a recently registered asset with a very short operational history. While the domain holds a valid SSL certificate issued by Let’s Encrypt, this does not mitigate the risk of impersonation or credential theft. Google Safe Browsing (GSB) status remains unverified due to the domain’s recent registration, and blocklist counts are pending broader threat intelligence dissemination. This domain is currently categorized as 'under_investigation' with an 'active' status, suggesting ongoing monitoring by cybersecurity teams. However, the lack of detections on VirusTotal and the absence of proactive blocking by security vendors pose a significant risk to end users. Immediate action is required to block tokensautofixss.xyz at the network and endpoint levels, update security policies to flag similar domains, and educate users about the dangers of brand impersonation scams. Until definitive action is taken, the residual risk remains high, particularly for individuals or organizations with exposure to cryptocurrency transactions involving OKX.

VirusTotal
VirusTotal
0 det.
URLScan
URLScan
Sertifikat TLS
Let's Encrypt
Usia
3 mo
Status terpantau
Terselubung · dapat dijangkau 502
PhishDestroy
Daftar Hapus
Terdaftar
Reports Sent
1
Cakupan data VirusTotal checked — no detections recorded URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture laporan yang disimpan URLScan verdict Analisis selesai Pemblokiran DNS tidak diperiksa TLS valid certificate, 86d WHOIS 3 mo old Tangkapan layar 3 captures · 3 sources Rantai pengalihan tidak diselidiki

Alur Tanggapan Ancaman Pipeline

Penemuan
Checks
Reports
Ketersediaan
12/13
Sent Report Recorded
Stored sent-report record for registrar OwnRegistrar, Inc., hosting provider, 1 abuse contact
abuse@ownregistrar.com
11/05/2026

Status Daftar Blokir Publik

Tangkapan tersimpan

Judul Halaman
Hyperliquid l Airdrop
Sertifikat TLS
Valid transport encryption · Diterbitkan oleh Let's Encrypt · valid for 86 days

Intelijen Domain

Domain
URLScan Verdict Analisis selesai score 0 report ↗
Server / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Reputasi Edge-IP tidak dikaitkan dengan domain ini.
Registrar OwnRegistrar US(US)
Alamat IP 172.67.203.57 CDN
LokasiCA Toronto, CA
JaringanAS13335 · Cloudflare, Inc.
IP asal tersembunyi di balik proksi CDN. Hasil IP terbalik untuk alamat edge berisi penyewa yang tidak terkait; menemukan asal memerlukan DNS pasif atau data transparansi sertifikat.
PendaftaranDibuat 11/05/2026 (100d)
Status HTTP502 Error
Cloaking Cloaking Detected Content divergence · score 2/6
transient_502: raw=transient_502; http=502; via=http_proxy
checked 19/08/2026
Elapsed Since First Report 3 days
Yang kami hitung Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Terselubung · dapat dijangkau.
Isi setiap laporan Catatan laporan keluar yang disimpan dapat merujuk pada bukti yang tersedia pada saat itu, seperti keputusan vendor, data pendaftaran, detail hosting, klasifikasi, atau tangkapan layar. Halaman ini tidak menyimpulkan secara pasti muatan yang dikirimkan, penerimaan, pengakuan, atau tindakan oleh penerima.
Rincian teknisDNS, SAN SSL, cap waktu
Pertama Kali Terdeteksi11/05/2026
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://tokensautofixss.xyz/
Server namaelle.ns.cloudflare.comgerald.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 08/05/2026scanned 11/05/2026
Case ID
ICANN OVERSIGHT

Akreditasi dan konteks RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Tidak ada yang dikirim secara otomatis.
Teknologi · 6 identified
Node.js
Programming languages

Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.

nodejs.org Keyakinan 100%
Vue.js
JavaScript frameworks

Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.

vuejs.org Keyakinan 100%
Nuxt.js
JavaScript frameworks Web frameworks Web servers Static site generator

Nuxt is a Vue framework for developing modern web applications.

nuxt.com Keyakinan 100%
Cloudflare Browser Insights
Analytics RUM

Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.

www.cloudflare.com Keyakinan 100%
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com Keyakinan 100%
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org Keyakinan 100%
Detected via Cloudflare Radar · Wappalyzer engine
Laporkan Domain Ini Kirimkan bukti & bantu lindungi orang lain

Analisis VirusTotal

0 detections recorded · vendor total unavailable
View on VT
Last analyzed
No VirusTotal engine marked the domain malicious in the stored analysis.

Bukti Terarsip

Wayback Machine Snapshot
Cuplikan sejarah tersedia untuk tinjauan bukti
View Archive
Analisis Performa Situs

Google PageSpeed Insights — mobile performance audit of tokensautofixss.xyz · checked May 11, 2026

61
Needs Work
Performance
FCP
2.41s
First Contentful Paint
LCP
6.26s
Largest Contentful Paint
CLS
0.07
Cumulative Layout Shift
TBT
484ms
Total Blocking Time
SI
2.41s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Bukti & Laporan Eksternal

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260511-B7E254 Recipient: abuse@ownregistrar.com
Page title stored with report: Hyperliquid l Airdrop
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 224.7 KB

Apakah Anda Terpengaruh oleh Situs Ini?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.

Europol
Temukan saluran pelaporan resmi untuk negara UE Anda
National police directory
Waspadalah terhadap penipu yang mengatasnamakan pemulihan! Penjahat dapat menghubungi korban lagi sambil berpura-pura menjadi penyelidik, pengacara, atau agen pemulihan. Jangan membayar biaya di muka atau membagikan kredensial. Pelajari lebih lanjut tentang penipuan dalam proses pemulihan →

Laporkan kepada Pihak Berwenang di Daerah Anda

Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.

Direktori 97 negara
Draf yang dibantu AI — detail insiden diproses oleh penyedia AI Tinjau dan kirimkan sendiri

Periksa Domain Apa Pun

Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik

Pindai Sekarang

Laporkan Phishing

Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas

Laporan

Pemberitahuan Ancaman Real-Time

Laporan phishing terbaru dan perubahan ketersediaan yang diamati

Pantau

Tetap Terinformasi, Tetap Aman

Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive

Pemberitahuan Ancaman Real-Time Ajukan Banding Terhadap Iklan Ini
HTML · IFRAME

Sematkan Laporan Ini

Bagikan informasi ancaman ini di situs web atau blog Anda

embed.html
<iframe
  src="https://phishdestroy.io/id/embed/domain/tokensautofixss.xyz"
  title="PhishDestroy threat report for tokensautofixss.xyz"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Surat Terima Kasih yang Sangat Tulus

Pembuat draf satir

Penerima
Konteks biaya

Draf satir. Angka biaya merupakan perkiraan; tidak diklaim bahwa angka tersebut secara tepat terkait dengan domain ini.