xertra[.]app
Verifica phishing e sicurezza per xertra.app
“$STRAX Airdrop”
xertra.app — Errore del server (HTTP 525). Tipo di truffa: Fake Airdrop. Riepilogo delle prove: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 68/100. Registrar: NiceNIC.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain xertra.app was registered on May 18, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. It resolves to the IP address 188.114.96.3, which is hosted by Cloudflare, Inc. in Canada. The site presents a valid TLS certificate issued by Let’s Encrypt (E7) and is served from the Cloudflare nameservers camilo.ns.cloudflare.com and serena.ns.cloudflare.com. An HTTP request returns status code 200, indicating the web server is actively delivering content.
The landing page is titled “$STRAX Airdrop” and matches the known “Airdrop Scam” phishing kit. The page mimics a cryptocurrency airdrop offer, attempting to harvest credentials from visitors. The domain appears in a single AlienVault OTX pulse and is listed on one public blocklist. PhishDestroy has already blocked the domain, and the Gridinsoft trust score is 0 out of 100, reflecting a lack of reputation.
Infrastructure analysis shows the use of Cloudflare’s reverse‑proxy service, which conceals the origin server and can complicate takedown efforts. No additional IP addresses or sub‑domains have been observed, and the site currently registers zero detections on VirusTotal out of 95 scans, which does not imply safety but highlights that the content has not yet been flagged by automated scanners. The lack of external references limits the ability to attribute the operation to a specific actor.
Continue analysis 1 more sections
Defenders should treat xertra.app as a high‑confidence malicious site. Immediate mitigation steps include adding the domain to URL filtering and DNS block lists, monitoring for similar airdrop‑related page titles, and enforcing TLS inspection to detect the Let’s Encrypt certificate fingerprint. Continuous observation of the associated IP 188.114.96.3 is advised, as changes in the hosting configuration could indicate a shift in the threat actor’s infrastructure.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:45:37 UTC
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.