xhamsternft[.]com
Verifica phishing e sicurezza per xhamsternft.com
“Buy xHamster NFT Collection: Send Rare NFTs to Your Crypto Wallet”
xhamsternft.com — Ultimo attivo conosciuto (HTTP 200). Tipo di truffa: Nft Scam. Riepilogo delle prove: VT 0/91; URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 0; PD 30/100. Registrar: Name.com.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy first observed xhamsternft.com on Mar 28, 2026. No available third-party check recorded a positive finding. Evidence score: 30/100.
VirusTotal recorded 0 detections among 91 engines on Aug 7, 2026 at 02:10 UTC. AlienVault OTX listed 4 community pulse references (not vendor detections) on Mar 30, 2026 at 07:06 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Jun 26, 2026 at 11:30 UTC. URLScan completed without a malicious verdict (score 0).
HTTP 200 was recorded on Aug 7, 2026 at 10:32 UTC. Registration records list Name.com, Inc. as the registrar and Mar 27, 2026 as the registration date. At collection time, the domain resolved to 188.114.96.3. Captured page title: “Buy xHamster NFT Collection: Send Rare NFTs to Your Crypto Wallet”. PhishDestroy classified the observed content as Nft Scam. IoC extraction completed on Jul 29, 2026 at 02:08 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis26/06/2026
This domain is flagged as an elevated-risk crypto drainer designed to deplete cryptocurrency wallets by impersonating a legitimate NFT collection. Analysis indicates the site mimics xHamster-branded digital assets, luring victims into connecting wallets under the pretense of purchasing rare NFTs. The underlying mechanism likely involves malicious smart contracts or wallet-draining scripts triggered upon interaction, a tactic increasingly observed in targeted attacks against crypto enthusiasts. Infrastructure analysis reveals the domain was registered on March 27, 2026, through Name.com, Inc., a registrar frequently associated with fraudulent activity. It resolves to the IP address 188.114.96.3, which may host additional malicious infrastructure. Detection metrics show minimal coverage, with only 1 of 95 security vendors flagging the domain on VirusTotal. The domain appears on a single security blocklist, while Gridinsoft assigns a trust score of 0/100. AlienVault OTX records the domain in four threat intelligence pulses, suggesting prior malicious activity. The SSL certificate, issued by Google Trust Services, provides a veneer of legitimacy but does not mitigate the underlying threat. Mitigation requires heightened vigilance from users engaging with NFT or crypto-related offers. Wallet holders should verify domain authenticity by cross-referencing official project channels and avoiding unsolicited NFT promotions. Browser-based wallet extensions with transaction simulation tools can preview contract interactions before execution, reducing exposure to drainer scripts. Organizations managing crypto assets should implement blocklists for known malicious domains and IPs, while monitoring for anomalous wallet activity indicative of unauthorized fund transfers. Given the domain's offline status, residual risk persists through potential redirects or re-registration under similar names.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
ICANN ha incassato. La responsabilità non è arrivata.
Per questo gTLD, il registrar indicato sopra opera in base a un contratto con ICANN. ICANN riscuote tariffe annuali, variabili e basate sulle transazioni, legate a registrazioni, rinnovi e trasferimenti.
Accreditamento: monetizzato. Responsabilità: ricontrollare più tardi.
Poi inizia la magia: ICANN scrive il RAA §3.18, il registrar indaga sugli abusi all’interno della propria base clienti e le vittime forniscono gratuitamente le prove, mentre ogni livello aspetta che agisca qualcun altro. Se questo fa sentire le vittime più al sicuro, eccellente — la fattura ha funzionato.
Tecnologie · 5 identified
Envoy is an open-source edge and service proxy, designed for cloud-native applications.
www.envoyproxy.io Confidenza al 100%Google Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com Confidenza al 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of xhamsternft.com · checked Jun 26, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Informazioni su questo rapporto: xhamsternft.com
Questo rapporto presenta le ultime prove archiviate disponibili per PhishDestroy. I timestamp della sorgente vengono mostrati ove disponibili; la disponibilità e i verdetti del fornitore possono cambiare dopo il ritiro.
Il sito acquisito mostrava il titolo della pagina “Buy xHamster NFT Collection: Send Rare NFTs to Your Crypto Wallet”.
PhishDestroy elenca xhamsternft.com come sospetto. È stato controllato dai motori di sicurezza 91; i verdetti automatizzati possono cambiare. Il monitoraggio continua.
Se ritieni che questo elenco sia impreciso, presentare ricorso. Per conoscere la nostra metodologia, visita Pagina delle domande frequenti.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo