migration-profitxrp[.]xyz
“Even geduld...”
migration-profitxrp.xyz — Contenuto non disponibile. Tipo di truffa: Crypto Drainer. Riepilogo delle prove: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. Registrar: NameSilo.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy identifies migration-profitxrp.xyz as an active high-risk phishing domain operating as an XRP-focused cryptocurrency drainer kit. The domain impersonates legitimate migration services to deceive users into connecting wallets and authorizing fraudulent transactions. Technical analysis confirms the presence of drainer scripts designed to siphon XRP and tokens under the guise of a wallet migration process. This campaign specifically targets XRP holders through social engineering tactics including fake migration portals and false upgrade notifications. The malicious infrastructure is hosted on Cloudflare’s CDN (clyde.ns.cloudflare.com, wren.ns.cloudflare.com) to evade detection and maintain operational uptime. This domain was registered on June 18, 2026 through NameSilo, LLC and resolves to IP address 104.21.76.92. PhishDestroy confirms VirusTotal detection at 1 out of 95 security vendors, indicating extremely low coverage despite confirmed malicious activity. Google Safe Browsing (GSB) has not yet flagged this domain, and current blocklist engagement remains minimal. The combination of recent registration, Cloudflare hosting, and low detection rate suggests a sophisticated, rapidly evolving threat likely leveraging zero-day evasion techniques. The XRP-specific drainer payload represents a targeted attack vector with potential for significant financial loss given XRP’s market presence. As of today, migration-profitxrp.xyz remains active and operational. Immediate response is required to prevent further victimization: block the domain at DNS and network levels, update firewall rules to drop traffic to 104.21.76.92, and issue advisories to XRP communities. While the domain shows signs of active phishing deployment, the low VT detection score (1/95) indicates a critical window where traditional defenses may fail. Users are strongly advised to verify all migration-related domains through official XRP Foundation channels and avoid wallet connections to unfamiliar websites. Remaining risk is classified as HIGH due to ongoing operation, low detection coverage, and the irreversible nature of cryptocurrency transactions.
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260624-B2548D Recipient: abuse@gen.xyz Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo