MALICIOUS — CRITICAL
proxif[.]ai
The domain proxif.ai was registered on April 09, 2026 through GoDaddy.com, LLC and is presently classified as a generic phishing site with a high risk rating.
- VirusTotal
- 3/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Ultimo attivo conosciuto · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
proxif.ai — Ultimo attivo conosciuto (HTTP 301). Tipo di truffa: Generic Phishing. Riepilogo delle prove: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 78/100. Registrar: GoDaddy.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain proxif.ai was registered on April 09, 2026 through GoDaddy.com, LLC and is presently classified as a generic phishing site with a high risk rating. The site presents a page titled “Proxifai – One Platform for the Entire Dev Lifecycle,” suggesting an attempt to masquerade as a legitimate development‑lifecycle service. The page returns an HTTP 301 redirect, indicating a possible staging step before delivering malicious content.
Infrastructure analysis shows the domain resolves to the IP address 188.114.96.3, which is owned by CloudFlare, Inc. and geolocated to Canada. The authoritative name servers are dina.ns.cloudflare.com and edward.ns.cloudflare.com, both associated with CloudFlare’s DNS service. The TLS certificate is issued by Google Trust Services under the WE1 certificate authority, providing a seemingly valid HTTPS façade that could lend credibility to the phishing attempt.
Threat intelligence reveals a Gridinsoft trust score of 0 out of 100, confirming the domain’s malicious nature. VirusTotal reports that 4 out of 95 scanned security vendors flag the domain as suspicious, and the domain appears on three external blocklists. It is already blocked by PhishDestroy, MetaMask, and SEAL, indicating that multiple security platforms have identified the site as a phishing vector. The combination of a fresh registration date, low trust score, and presence on blocklists supports the high‑risk assessment.
Defenders should immediately add proxif.ai to network and endpoint blocklists, enforce DNS filtering for its IP address 188.114.96.3, and monitor for any traffic to the associated CloudFlare name servers. Continuous vigilance is advised, as the active status suggests the operator may still be distributing phishing pages. Organizations should also educate users about the fake “Proxifai” branding to reduce successful credential harvesting attempts.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of proxif.ai · checked Apr 9, 2026
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.