etherexes[.]xyz
証拠の概要
The domain etherexes.xyz was observed on July 23, 2026 as an offline generic phishing site with an elevated risk rating. Registration records show the domain was created through PDR Ltd. d/b/a PublicDomainRegistry.com, indicating a public‑domain registrar often used for rapid domain turnover. DNS resolution points to the IP address 104.21.85.180, which belongs to AS13335 Cloudflare, Inc., a cloud‑based content delivery network located in the United States. The site presented a TLS certificate issued by Google Trust Services under the WE1 label, confirming that HTTPS was correctly negotiated despite the site being inaccessible. HTTP requests returned a 403 status code, and the only visible page title was "Just a moment..." suggesting a Cloudflare challenge page rather than a content payload. Infrastructure analysis detected Cloudflare services and HTTP/3 protocol support, confirming the use of modern delivery mechanisms.
Threat intelligence indicates the domain appears on a single security blocklist and is actively blocked by the PhishDestroy feed. VirusTotal scans recorded two detections out of ninety‑five scanning engines, providing limited but corroborating evidence of malicious activity. No additional intelligence such as brand targeting, specific phishing kits, or detailed payloads is available, and the lack of listed nameservers prevents deeper DNS‑level attribution.
Defenders should continue to block etherexes.xyz at the network perimeter and incorporate the domain into endpoint and web‑filtering policies. Given the Cloudflare hosting, future variants may appear on adjacent IP ranges; therefore, monitoring for new domains resolving to the same AS13335 prefix is advisable. Regular re‑query of threat‑intel feeds, including PhishDestroy and VirusTotal, will ensure timely detection of any re‑activation.
Data Coverage
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月13日
検出タイムライン
-
ドメイン状態
到達可能 → 到達不能
-
ドメイン状態
到達可能 → 到達不能
-
Cloudflare Radar
Cloudflare Radar スキャンを保存 · スキャンを開く
-
ドメイン状態
到達不能 → 到達可能
保存済みキャプチャ
ドメイン・インテリジェンス
技術詳細DNS、TLS 名、タイムスタンプ
ICANN OVERSIGHT
認定と RAA の背景
認定と RAA の背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
使用技術
高確信度で特定された技術:2 件
VirusTotalによる分析
アーカイブ済み証拠
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください