uisdthedai[.]xyz
“$CHIP | USD AI”
uisdthedai.xyz — Contenuto non disponibile (HTTP 502). Simulazione del marchio: Genericcrypto; Tipo di truffa: Fake Exchange. Riepilogo delle prove: VirusTotal 12/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 1 alert; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. Registrar: Dynadot.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy identifies uisdthedai.xyz as a recently activated domain engaged in crypto drainer phishing activity, likely targeting cryptocurrency users through deceptive transaction interfaces. The domain does not directly impersonate a specific brand but leverages generic crypto-related terminology to lure victims into connecting wallets or approving fraudulent transactions. Initial forensic analysis suggests this threat utilizes a drainer kit designed to silently siphon funds from connected wallets upon user interaction, though the exact payload and distribution vectors remain under investigation. This domain exhibits multiple indicators of malicious intent. VirusTotal currently reports 12/95 detections, indicating it has evaded automated scanners at the time of assessment. The domain resolves to IP address 188.114.97.3 and was registered through Dynadot LLC on April 02, 2026. The SSL certificate is issued by Let's Encrypt, which is commonly abused for short-lived phishing operations. As of this report, the domain remains unlisted on Google Safe Browsing (GSB) and has not been flagged by major threat intelligence blocklists, leaving users vulnerable during this early stage of deployment. The domain's age and clean reputation metrics suggest a deliberate effort to avoid detection while the infrastructure is primed for malicious operations. The current status of this threat is active and under active investigation by PhishDestroy's threat intelligence team. Immediate defensive actions include domain blocking at the network perimeter and user awareness campaigns highlighting the risks of unsolicited crypto-related domains. While the domain's technical indicators show low detection rates, the combination of recent registration, active resolution, and drainer kit deployment elevates the risk to users interacting with crypto platforms. Remaining risk factors include potential domain rotation, payload evolution, and expansion into targeted phishing campaigns. Users are strongly advised to verify any crypto-related domains using PhishDestroy's real-time scanning tools and to avoid interacting with unsolicited wallet connection requests.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | uisdthedai.xyz |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Informazioni forensi
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of uisdthedai.xyz · checked Apr 4, 2026
Dati e relazioni esterne
PD-20260404-CEBB88 Recipient: abuse@dynadot.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo