Vai al rapporto di sicurezza
Checked 09/08/2026 Ref 4D92723D

MALICIOUS — CRITICAL

app.apyxfi.com Crypto Drainer Impersonates DeFi Platforms

app[.]apyxfi[.]com

PhishDestroy has flagged app.apyxfi.com as an active crypto drainer under investigation, posing as a legitimate DeFi platform to steal cryptocurrency assets.

89/100 evidence score · Critical
VirusTotal
13/91
Blocklists
1 · ScamSniffer
Disponibilità
Ammantato · raggiungibile · HTTP 502
Report / Add Evidence Appeal this listing
2026-05-05 04:12 UTCAmmantato · raggiungibile · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Questo dominio è stato segnalato come dannoso
Motori di sicurezza che segnalano un rilevamento: 13. Blocklist pubbliche che segnalano una corrispondenza: 1. Prestare estrema cautela: non inserire credenziali o informazioni personali.
Jump to section
Riepilogo del rapporto

app.apyxfi.com — Ammantato · raggiungibile (HTTP 502). Simulazione del marchio: Google; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLScan malicious verdict; 1 external blocklist match (ScamSniffer); cloaking observed; PhishDestroy score 89/100. Registrar: Namecheap.

L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.

Evidence Analysis

Ref 4D92723D

PhishDestroy has flagged app.apyxfi.com as an active crypto drainer under investigation, posing as a legitimate DeFi platform to steal cryptocurrency assets. This domain is specifically designed to deceive users into connecting their wallets, resulting in unauthorized fund transfers. The threat level remains under_investigation due to ongoing analysis, but the presence of a crypto drainer mechanism elevates the risk to critical levels for unsuspecting users. This domain was registered through NAMECHEAP INC on March 12, 2026, and currently resolves to the IP address 104.21.79.140. The SSL certificate is issued by Let's Encrypt, which does not inherently indicate legitimacy. VirusTotal currently shows 13/95 detections, meaning it has not yet been flagged by security vendors, likely due to its recent creation. The domain's age and lack of historical data contribute to its stealthy nature, making it harder to detect through traditional means. The absence of blocklist entries further underscores the need for proactive monitoring and user awareness. To mitigate the risk posed by app.apyxfi.com, users should refrain from visiting or interacting with the domain, especially avoiding any wallet connection prompts. Organizations and security teams should block the domain and IP address (104.21.79.140) at the network level to prevent accidental exposure. Implementing browser-based protections, such as DNS filtering or security extensions that detect crypto drainer domains, is strongly recommended. Additionally, users should verify the authenticity of DeFi platforms through official channels before engaging in any transactions. Immediate reporting of this domain to security vendors and platforms like VirusTotal can help increase its detection rate and protect the broader community from potential attacks.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
13 det.
URLScan
URLScan
Certificato TLS
Let's Encrypt
Età
5 mo
Stato osservato
Ammantato · raggiungibile 502
PhishDestroy
Elenco da eliminare
In elenco
Reports Sent
1
Copertura dei dati12 recorded checks
VirusTotal 13 / 91 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture rapporto memorizzato URLScan verdict malicious Blocchi DNS 14 verificato — nessun blocco TLS valid certificate, 42d WHOIS 5 mo old Screenshot 3 captures · 3 sources Catena di reindirizzamenti non sondato

Pipeline di risposta alle minacce

Scoperta
Checks
Reports
Disponibilità
13/14
Minaccia rilevata
app.apyxfi.com rilevati e inseriti in coda per un’analisi completa
05/05/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
URLScan Verdict
URLScan returned a malicious verdict · score 100
29/07/2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
Web Archive
Preserved in Wayback Machine — historical evidence archived
05/05/2026
VirusTotal
13/91 recorded on VirusTotal
14/06/2026
Google Safe Browsing
05/05/2026
Rilevamento delle liste di blocco
Si trova in 1 blocklist: ScamSniffer
09/08/2026
Brand Impersonation
Impersonation of Google
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
Technical Analysis Recorded
Il report contiene tecnologia archiviata o risultati di analisi forensi.
09/08/2026
Sent Report Recorded
Stored sent-report record for registrar NAMECHEAP INC, hosting provider, 1 abuse contact
abuse@namecheap.com
05/05/2026
DestroyList pubblicato
05/05/2026
Monitoring Continues
Il dominio rimane raggiungibile o ad accesso limitato; controlli futuri potrebbero aggiornare questa osservazione.

Stato della lista di blocco pubblica

Acquisizione salvata

Titolo della pagina
Google
Certificato TLS
Valid transport encryption · Emesso da Let's Encrypt · valid for 42 days

Analisi dei domini

Dominio
URLScan Verdict Malevolo score 100 Phishing report ↗
Telegram IoCs 1 extracted https://t.me/apyx_announcements
Server / ASN gws · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden La reputazione Edge-IP non è attribuita a questo dominio.
Registrar (base domain) Namecheap IS(IS)
Indirizzo IP 104.21.79.140 CDN
PosizioneCA Toronto, CA
ReteAS13335 · Cloudflare, Inc.
L'IP di origine è nascosto dietro un proxy CDN. I risultati dell'IP inverso per l'indirizzo edge contengono tenant non correlati; la ricerca dell'origine richiede DNS passivo o dati di trasparenza del certificato.
Registration (base domain)apyxfi.com · Creato 12/03/2026 (149d)
Stato HTTP502 Error
Cloaking Cloaking Detected Bot redirect safe · score 3/6
transient_502: raw=transient_502; http=502; via=http_proxy
checked 09/08/2026
Elapsed Since First Report 7 days
Cosa conteggiamo Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Ammantato · raggiungibile.
Cosa contiene ogni rapporto I record archiviati dei report in uscita possono fare riferimento a prove disponibili in quel momento, come verdetti dei fornitori, dati di registrazione, dettagli di hosting, classificazioni o screenshot. Questa pagina non deduce l'esatto carico utile consegnato, la ricevuta, la conferma o l'azione da parte di un destinatario.
Dettagli tecniciDNS, SAN SSL, timestamp
Rilevato per la prima volta05/05/2026
IoC Extractionscanned 01/08/20260 wallet · 1 Telegram IoC
Submitted URLhttp://app.apyxfi.com/
Nameserverhank.ns.cloudflare.comkarina.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 18/03/2026scanned 05/05/2026
TLS SAN Domainsapyxfi.com
Case ID
ICANN OVERSIGHT Registration: apyxfi.com

Accreditamento e contesto RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain apyxfi.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nulla viene inviato automaticamente.
Tecnologie · 3 identified
Google Web Server
Web servers

Web server software.

en.wikipedia.org Confidenza al 100%
HSTS
Sicurezza

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org Confidenza al 100%
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org Confidenza al 100%
Detected via Cloudflare Radar · Wappalyzer engine
Segnala questo dominio Invia le prove e contribuisci a proteggere gli altri

Analisi di VirusTotal

13 / I fornitori di sicurezza 91 hanno contrassegnato questo dominio
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
Sophos

Prove archiviate

Wayback Machine Snapshot
È disponibile un'istantanea storica per la revisione delle prove
View Archive
Analisi delle prestazioni del sito

Google PageSpeed Insights — mobile performance audit of app.apyxfi.com · checked May 5, 2026

79
Needs Work
Performance
FCP
1.69s
First Contentful Paint
LCP
1.85s
Largest Contentful Paint
CLS
0.023
Cumulative Layout Shift
TBT
825ms
Total Blocking Time
SI
1.95s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.

Europol
Trova il canale di segnalazione ufficiale per il tuo paese dell'UE
National police directory
Attenzione ai truffatori che promettono il recupero dei fondi! I criminali possono contattare nuovamente le vittime fingendo di essere investigatori, avvocati o agenti di recupero. Non pagare commissioni anticipate né condividere credenziali. Scopri di più sulle frodi relative ai sussidi di recupero →

Segnalalo alle autorità locali

Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.

Elenco di 97 paesi
Bozza assistita dall'intelligenza artificiale: i dettagli dell'incidente vengono elaborati dal fornitore di intelligenza artificiale Controllalo e invialo tu stesso
Incorpora questo rapportoRead-only HTML widget
HTML · IFRAME

Incorpora questo rapporto

Condividi queste informazioni sulle minacce sul tuo sito web o sul tuo blog

embed.html
<iframe
  src="https://phishdestroy.io/it/embed/domain/app.apyxfi.com"
  title="PhishDestroy threat report for app.apyxfi.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Una lettera di ringraziamento molto sincera

Generatore di bozze satiriche

Destinatario
Contesto delle tariffe

Bozza satirica. Gli importi delle tariffe sono stime; non si afferma che siano attribuibili esattamente a questo dominio.