MALICIOUS — CRITICAL
tirox[.]cc
PhishDestroy has begun tracking tirox.cc as an active generic-phishing domain designed to steal online account credentials.
- VirusTotal
- 7/91
- Blocklists
- No stored match
- Disponibilità
- Contenuto non disponibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
tirox.cc — Contenuto non disponibile (HTTP 502). Simulazione del marchio: Genericcrypto; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 7/91 (alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 75/100. Registrar: NiceNIC.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy has begun tracking tirox.cc as an active generic-phishing domain designed to steal online account credentials. Visitors presented with spoofed login forms are prompted for usernames, passwords, or multi-factor codes under false pretenses, allowing attackers to hijack accounts across banking, email, and social platforms. Reports so far confirm the site has not yet been blocked by any of the 95 antivirus scanners on VirusTotal, indicating threat actors may still be actively iterating on the lure.
This domain was flagged by PhishDestroy’s behavioral pipeline after it was registered on 26 February 2026 via NICENIC INTERNATIONAL GROUP CO., LIMITED and began resolving to Internet-facing IP 188.114.97.3. Certificate transparency logs show Let’s Encrypt issued a TLS certificate on the same day, suggesting the attackers moved quickly to host a seemingly legitimate but entirely fraudulent site. The 7/95 VirusTotal count illustrates how new domains can bypass signature-based detection until user or community reporting tips the scales.
If you visited tirox.cc and entered any credentials, immediately change those passwords on a known-good device and enable multi-factor authentication where available. Next, revoke any session tokens or API keys tied to the exposed account. Report the incident to your organization’s security team and file a complaint with the platform you believe was mimicked. Consider running a reputable malware scan and monitor financial or cloud storage accounts for unusual activity for at least 30 days. When in doubt, navigate directly to the official site via a bookmark or manually typed URL instead of following any link or QR code.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | tirox.cc |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Latest Classified Outcome 2026-08-09 04:27:04 UTC
Tecnologie · 4 identified
Twitter Ads is an advertising platform for Twitter 'microblogging' system.
ads.twitter.com Confidenza al 100%Facebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.
facebook.com Confidenza al 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of tirox.cc · checked May 5, 2026
Dati e relazioni esterneIndependent lookups and source reports
PD-20260505-CE40AC Recipient: abuse@nicenic.net Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.