xrpfi-flare[.]com
“XRPFi · Earn FXRP Yields on Flare”
xrpfi-flare.com — Kesalahan server (HTTP 502). Peniruan identitas merek: Flare; Jenis penipuan: Investment Scam. Ringkasan bukti: VirusTotal 8/92 (ChainPatrol, alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker); Spamhaus DBL_PHISH; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 74/100. Registrar: NiceNIC.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, xrpfi-flare.com, operates as an active credential harvesting platform impersonating the Flare Network, a blockchain infrastructure provider. The site presents itself as a yield-generating service for FXRP tokens, using the page title 'XRPFi · Earn FXRP Yields on Flare' to deceive users into submitting wallet credentials or private keys. The fraudulent interface mimics legitimate decentralized finance (DeFi) platforms, increasing the likelihood of successful social engineering attacks against Flare Network participants seeking staking or yield opportunities.
Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain was registered on May 8, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with phishing operations. It resolves to the IP address 188.114.97.3 and is flagged by 8 out of 95 security vendors on VirusTotal, with an additional presence on four distinct security blocklists. Detection engines including MetaMask, PhishDestroy, SEAL, and ScamSniffer have classified the domain as malicious. Threat intelligence platforms such as AlienVault OTX have recorded the domain in at least one threat pulse, further corroborating its association with fraudulent campaigns. The site employs Cloudflare for content delivery and security, a common tactic among threat actors to obfuscate origin infrastructure and evade detection.
Users who have visited xrpfi-flare.com or interacted with its content are advised to take immediate remedial action. Any credentials, private keys, or wallet recovery phrases entered on the site should be considered compromised. Affected individuals must transfer assets from exposed wallets to new, secure addresses and revoke any connected smart contract approvals. Monitoring for unauthorized transactions is critical, and users should report the incident to relevant blockchain security response teams. Proactive measures include verifying domain authenticity through official Flare Network communication channels and employing browser-based security extensions that detect brand impersonation in real time.
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-15 03:33:07 UTC
Teknologi · 4 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Keyakinan 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Keyakinan 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Keyakinan 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Keyakinan 100%Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260508-29EC48 Recipient: abuse@nicenic.net Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive