xshell-cn[.]com
Pemeriksaan phishing dan keamanan xshell-cn.com
“Xshell中文版下载 - Xshell官网”
xshell-cn.com — Konten tidak tersedia (HTTP 502). Ringkasan bukti: VT 19/93 (SOCRadar); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 2 (MetaMask, SEAL); PD 100/100. Registrar: Dominet (HK).
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
PhishDestroy first observed xshell-cn.com on Feb 4, 2026. Positive findings were recorded by VirusTotal, MetaMask, and SEAL. Evidence score: 100/100.
VirusTotal recorded 19 detections among 93 engines: SOCRadar on May 14, 2026 at 20:00 UTC. The external blocklist snapshot contained 2 matches (MetaMask, SEAL) on Aug 7, 2026 at 10:20 UTC. URLQuery recorded no positive detection on Feb 4, 2026 at 17:46 UTC. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0) on Feb 4, 2026 at 11:50 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:29 UTC; content was unavailable. Registration records list Dominet (HK) Limited as the registrar. At collection time, the domain resolved to 172.67.218.40. Captured page title: “Xshell中文版下载 - Xshell官网”. DOM analysis completed on Apr 23, 2026 at 07:20 UTC; stored DOM score 0/100. IoC extraction completed on Aug 2, 2026 at 04:14 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis25/06/2026
This domain, xshell-cn.com, poses a significant credential and malware distribution threat by impersonating the official Xshell software download portal. Analysis indicates the site presents itself as a Chinese-language version of Xshell, a popular terminal emulator, with the page title 'Xshell中文版下载 - Xshell官网.' Users visiting this domain risk exposure to counterfeit installers bundled with backdoors, keyloggers, or other malicious payloads designed to compromise systems or harvest sensitive credentials. The fraudulent nature of this site is further evidenced by its deceptive design, which closely mimics legitimate software distribution platforms to exploit trust in the Xshell brand. Infrastructure analysis reveals multiple technical indicators confirming the malicious intent of xshell-cn.com. The domain was registered on February 21, 2026, through Dominet (HK) Limited, a registrar frequently associated with suspicious or high-risk domains. It resolves to the IP address 172.67.218.40, hosted on Cloudflare's network (AS13335), a common tactic to obscure the true origin of malicious infrastructure. The domain lacks an SSL certificate, increasing the risk of man-in-the-middle attacks or data interception. Detection metrics further underscore its threat level: 19 out of 95 security vendors on VirusTotal flag the domain as malicious, and it appears on three independent security blocklists, including PhishDestroy, MetaMask, and SEAL. The domain's current offline status suggests takedown action, but its prior activity remains a concern for historical exposure. Users who visited xshell-cn.com or interacted with its content should take immediate remedial steps to mitigate potential compromise. First, disconnect the affected device from networks to prevent lateral movement of any installed malware. Conduct a full system scan using updated antivirus or endpoint detection tools to identify and remove malicious artifacts. If credentials were entered on the site, reset passwords for all associated accounts, prioritizing those with administrative or financial access. Monitor accounts for unauthorized activity, such as logins from unfamiliar locations or devices. Additionally, review installed applications for any unauthorized or suspicious software that may have been downloaded from the domain. Organizations should consider isolating affected endpoints and conducting a forensic analysis to determine the scope of compromise. Awareness of this domain's tactics can help prevent future incidents; always verify software downloads through official vendor channels and inspect domain registration details for anomalies.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
ICANN Sudah Dibayar. Akuntabilitas Tak Kunjung Datang.
Untuk gTLD ini, registrar di atas beroperasi berdasarkan kontrak dengan ICANN. ICANN memungut biaya tahunan, biaya variabel, dan biaya berbasis transaksi yang terkait dengan pendaftaran, perpanjangan, dan transfer.
Akreditasi: dimonetisasi. Akuntabilitas: silakan periksa kembali nanti.
Lalu keajaiban dimulai: ICANN menulis RAA §3.18, registrar menyelidiki penyalahgunaan di dalam basis pelanggannya sendiri, dan para korban menyerahkan bukti secara cuma-cuma sementara setiap lapisan menunggu pihak lain bertindak. Jika itu membuat para korban merasa lebih aman, bagus sekali—ternyata tagihannya bekerja.
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Tentang Laporan Ini: xshell-cn.com
Laporan ini menyajikan bukti tersimpan terbaru yang tersedia untuk PhishDestroy. Stempel waktu sumber ditampilkan jika tersedia; ketersediaan dan keputusan vendor dapat berubah setelah pengumpulan.
Situs yang diambil menampilkan judul halaman “Xshell中文版下载 - Xshell官网”.
Pada 07/08/2026, xshell-cn.com memiliki deteksi dari mesin keamanan 19.
Jika Anda yakin daftar ini tidak akurat, mengajukan banding. Untuk mempelajari metodologi kami, kunjungi halaman pertanyaan umum.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive