xconnexion[.]co[.]za
“Xconnexion – Online Shopping”
xconnexion.co.za — Ammantato · raggiungibile. Simulazione del marchio: Across; Tipo di truffa: Impersonation. Riepilogo delle prove: VirusTotal 16/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); Google Safe Browsing flagged; cloaking observed; PhishDestroy score 100/100. Registrar: Woza Domains.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
The domain xconnexion.co.za is identified as a high-risk brand impersonation threat currently offline. Analysis confirms the site was designed to mimic Across, a legitimate platform, using a fabricated e-commerce interface titled 'Xconnexion – Online Shopping.' This fraudulent operation aimed to deceive users into engaging with counterfeit storefronts, likely for credential harvesting or financial fraud. Infrastructure analysis reveals the domain was registered on January 28, 2022, through Woza Domains and resolved to the IP address 91.121.60.232, hosted on OVH SAS infrastructure in France (AS16276). The site was flagged by 16 of 95 security vendors on VirusTotal, with detection entries on three prominent blocklists, including PhishDestroy, MetaMask, and SEAL. Google Safe Browsing classified the domain as phishing, and its SSL certificate was issued by Let's Encrypt (R13), a common choice for malicious actors due to its low-cost and automated issuance process. The combination of these indicators—low-reputation registrar, offshore hosting, and multiple security flags—reinforces the high-risk classification. As of the latest assessment, xconnexion.co.za has been taken offline, likely due to enforcement actions or infrastructure takedowns. However, the domain remains a potential threat vector if reactivated. Organizations and users are advised to block the domain at the DNS or firewall level, monitor for re-registration attempts, and educate stakeholders on recognizing brand impersonation tactics. Security teams should review logs for prior interactions with 91.121.60.232 or related subdomains and assess any exposure to fraudulent transactions linked to this campaign. Proactive measures, such as implementing strict certificate validation and domain reputation checks, are recommended to mitigate similar threats.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 1 identified
HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of xconnexion.co.za · checked Mar 1, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo