Vai al rapporto di sicurezza
Checked 09/08/2026 Ref 59634482

MALICIOUS — HIGH

xihlukeit[.]com

4 of 91 security engines flagged the domain; the latest stored check returned HTTP 403.

65/100 evidence score · High
VirusTotal
4/91
Blocklists
No stored match
Disponibilità
Raggiungibile · accesso limitato · HTTP 403
Report / Add Evidence Appeal this listing
2026-03-24 11:51 UTCRaggiungibile · accesso limitato · HTTP 403

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Questo dominio è stato segnalato come dannoso
Motori di sicurezza che segnalano un rilevamento: 4. Prestare estrema cautela: non inserire credenziali o informazioni personali.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@godaddy.com. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
5 months
Reports sent
1
Latest case ID
PD-20260306-A8482C
Current status
HTTP 403 at latest stored check
Jump to section
Riepilogo del rapporto

xihlukeit.com — Raggiungibile · accesso limitato (HTTP 403). Tipo di truffa: Fake Exchange. Riepilogo delle prove: VirusTotal 4/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft); PhishDestroy score 65/100. Registrar: GoDaddy.

L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.

Evidence Digest

Ref 59634482

xihlukeit.com is classified high with an evidence score of 65/100. 4 of 91 security engines flagged the domain. Registered 6 Mar 2026 via GoDaddy.com, LLC, hosted on 104.21.60.93 (CLOUDFLARENET - Cloudflare, Inc., US, US). The latest stored check on 9 Aug 2026 returned HTTP 403 and includes a capture. 1 outgoing abuse report is recorded, most recently on 6 Mar 2026.

Stored generated summary (templated)cerebras · 24/07/2026

Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.

Analysis of xihlukeit.com shows the domain was registered on March 6, 2026 through GoDaddy.com, LLC. The authoritative nameservers are grannbo.ns.cloudflare.com and noah.ns.cloudflare.com, indicating that the zone is hosted on Cloudflare’s network. DNS resolution points to IP address 104.21.60.93, which belongs to AS13335 (Cloudflare, Inc.) and is geolocated to the United States. The site presented a TLS certificate issued by Let’s Encrypt (identifier “E7”), confirming that HTTPS was enabled. An HTTP request returned a 403 status code, suggesting the site is currently inaccessible or deliberately restricted, and the domain is listed as offline in threat‑intelligence feeds.

The page title retrieved from the domain reads “Xihlukeit — Secure Cryptocurrency Trading Platform,” and the threat classification is recorded as a “Fake Exchange.” VirusTotal records indicate that 1 of 95 scanning engines flagged the domain as malicious, and the domain appears on a single external blocklist, specifically PhishDestroy, which has taken the domain down. The combination of a recent creation date, a reputable registrar, Cloudflare hosting, a legitimate‑looking TLS certificate, and a cryptocurrency‑focused title is consistent with a typical credential‑harvesting or financial‑fraud operation that masquerades as a legitimate trading platform. While the limited number of vendor detections suggests a low detection coverage, the presence on a phishing blocklist and the explicit “Fake Exchange” label provide sufficient confidence to treat the domain as malicious.

Uncertainty remains regarding the exact payload or credential‑capture mechanisms, as no page content analysis is available beyond the title. Defenders should add the domain to deny‑list rules at network and endpoint layers, monitor for DNS queries to the associated IP range, and consider tightening email filters for any communications referencing “Xihlukeit” or similar cryptocurrency‑trading language.

VirusTotal
VirusTotal
4 det.
URLScan
URLScan
Certificato TLS
Scaduto o non verificato -73d
Età
5 mo
Stato osservato
Raggiungibile · accesso limitato 403
PhishDestroy
Elenco da eliminare
In elenco
Reports Sent
1
Copertura dei dati12 recorded checks
VirusTotal 4 / 91 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references CF Radar no data URLScan capture rapporto memorizzato URLScan verdict Analisi completata Blocchi DNS non controllato TLS Scaduto o non verificato WHOIS 5 mo old Screenshot 3 captures · 3 sources Catena di reindirizzamenti non sondato

Pipeline di risposta alle minacce

Scoperta
Checks
Reports
Disponibilità
13/14
Sent Report Recorded
Stored sent-report record for registrar GoDaddy.com, LLC, hosting provider, 1 abuse contact
abuse@godaddy.com
06/03/2026

Stato della lista di blocco pubblica

Acquisizione salvata

Titolo della pagina
Xihlukeit — Secure Cryptocurrency Trading Platform
Certificato TLS
Scaduto o non verificato · Emesso da Let's Encrypt / E7

Analisi dei domini

Dominio
URLScan Verdict Analisi completata score 0 report ↗
Server / ASN cloudflare · AS13335 CLOUDFLARENET - Cloudflare, Inc., US
IP Context Cloudflare shared edge origin IP hidden La reputazione Edge-IP non è attribuita a questo dominio.
Registrar GoDaddy US(US)
Indirizzo IP 104.21.60.93 CDN
PosizioneUS San Francisco, US
ReteAS13335 · Cloudflare, Inc.
L'IP di origine è nascosto dietro un proxy CDN. I risultati dell'IP inverso per l'indirizzo edge contengono tenant non correlati; la ricerca dell'origine richiede DNS passivo o dati di trasparenza del certificato.
RegistrazioneCreato 06/03/2026 (156d)
Stato HTTP403 Forbidden
Elapsed Since First Report 7 days
Cosa conteggiamo Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Raggiungibile · accesso limitato.
Cosa contiene ogni rapporto I record archiviati dei report in uscita possono fare riferimento a prove disponibili in quel momento, come verdetti dei fornitori, dati di registrazione, dettagli di hosting, classificazioni o screenshot. Questa pagina non deduce l'esatto carico utile consegnato, la ricevuta, la conferma o l'azione da parte di un destinatario.
Dettagli tecniciDNS, SAN SSL, timestamp
Rilevato per la prima volta06/03/2026
DOM Analysisanalyzed 28/07/2026score 0/100
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://xihlukeit.com/
Nameservernoah.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 28/02/2026scanned 15/03/2026
Case ID
ICANN OVERSIGHT

Accreditamento e contesto RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nulla viene inviato automaticamente.
Segnala questo dominio Invia le prove e contribuisci a proteggere gli altri

Analisi di VirusTotal

4 / I fornitori di sicurezza 91 hanno contrassegnato questo dominio
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
alphaMountain.ai
CRDF
Fortinet
Gridinsoft

Prove archiviate

Wayback Machine Snapshot
È disponibile un'istantanea storica per la revisione delle prove
View Archive
Analisi della configurazione del sito
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.

Europol
Trova il canale di segnalazione ufficiale per il tuo paese dell'UE
National police directory
Attenzione ai truffatori che promettono il recupero dei fondi! I criminali possono contattare nuovamente le vittime fingendo di essere investigatori, avvocati o agenti di recupero. Non pagare commissioni anticipate né condividere credenziali. Scopri di più sulle frodi relative ai sussidi di recupero →

Segnalalo alle autorità locali

Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.

Elenco di 97 paesi
Bozza assistita dall'intelligenza artificiale: i dettagli dell'incidente vengono elaborati dal fornitore di intelligenza artificiale Controllalo e invialo tu stesso
Incorpora questo rapportoRead-only HTML widget
HTML · IFRAME

Incorpora questo rapporto

Condividi queste informazioni sulle minacce sul tuo sito web o sul tuo blog

embed.html
<iframe
  src="https://phishdestroy.io/it/embed/domain/xihlukeit.com"
  title="PhishDestroy threat report for xihlukeit.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Una lettera di ringraziamento molto sincera

Generatore di bozze satiriche

Destinatario
Contesto delle tariffe

Bozza satirica. Gli importi delle tariffe sono stime; non si afferma che siano attribuibili esattamente a questo dominio.