amptox29[.]xyz
“Under construction - Awesome site in the making!”
amptox29.xyz — Non verificato. Tipo di truffa: Generic Phishing. Riepilogo delle prove: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 1 alert; PhishDestroy score 78/100. Registrar: Dynadot.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy identifies amptox29.xyz as an active crypto drainer phishing domain currently under investigation. The domain specifically targets cryptocurrency users by mimicking legitimate platforms to siphon funds through deceptive transactions. Security teams have confirmed the threat actor’s infrastructure remains operational, warranting heightened vigilance for associated domains and IPs. This domain was flagged by 1 of 95 VirusTotal vendors as of the latest scan, indicating its recent emergence and low detection coverage. It resolves to IP 35.213.153.38, registered through Dynadot LLC on April 22, 2026. Notably, it utilizes a Let’s Encrypt SSL certificate, which may lend false legitimacy to potential victims. The domain’s age and lack of blocklist entries (0 detections) suggest it is a fresh campaign, likely leveraging newly registered infrastructure to evade early-stage defenses. As the investigation progresses, users are strongly advised to avoid interacting with amptox29.xyz or any subdomains/resolving IPs. Organizations should implement network-level blocks for the offending IP (35.213.153.38) and monitor for DNS resolutions to this domain. Cryptocurrency platforms must enhance user education regarding crypto drainer tactics, emphasizing verification of transaction URLs via trusted sources like PhishDestroy. Security teams are urged to treat this domain as a high-priority indicator of compromise (IOC) and share telemetry to accelerate mitigation efforts.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | amptox29.xyz |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org Confidenza al 100%Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of amptox29.xyz · checked May 13, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo