lxlis[.]cfd
lxlis.cfd のフィッシング・安全性チェック
“403 Forbidden”
lxlis.cfd — コンテンツが利用できません (HTTP 502). 詐欺タイプ: Credential Phishing. 証拠の概要: VT 5/91 (alphaMountain.ai, Ermes, Fortinet, Gridinsoft, SOCRadar); URLQuery 0; URLScan no malicious verdict; GSB no flag; Spamhaus DBL_SPAM; BL 0; PD 83/100. レジストラ: NiceNIC.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
PhishDestroy first observed lxlis.cfd on Jun 28, 2026. The captured page title is “403 Forbidden”. Stored page analysis classifies the content as credential phishing. Current evidence score: 83/100 (critical).
Positive findings are stored from 2 sources: VirusTotal and Spamhaus DBL. VirusTotal recorded 5 detections among 91 engines: alphaMountain.ai, Ermes, Fortinet, Gridinsoft, SOCRadar on Jul 5, 2026 at 22:18 UTC. Spamhaus DBL: DBL_SPAM on Jun 28, 2026 at 14:30 UTC. Non-positive and contextual checks: The external blocklist snapshot contained no matches on Aug 7, 2026 at 22:20 UTC. URLQuery recorded no positive detection; no observation timestamp was retained. Google Safe Browsing returned no flag on Jun 28, 2026 at 11:30 UTC. URLScan completed without a malicious verdict (score 0) on Jul 29, 2026 at 03:02 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:35 UTC; content was unavailable. Latest classified outcome: registration hold observed; cause registrar client hold; mechanism client hold; observed actor NICENIC INTERNATIONAL GROUP CO., LIMITED on Aug 6, 2026 at 02:01 UTC. Registration records for the domain list NICENIC INTERNATIONAL GROUP CO., LIMITED as the registrar and Jun 26, 2026 as the creation date. Registration preceded first observation by 1 day. At collection time, the hostname resolved to 104.21.11.233 on AS13335 (Cloudflare, Inc.). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. DOM analysis on Jun 28, 2026 at 14:20 UTC returned 83/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. TLS metadata lists Google Trust Services / WE1 as the certificate issuer with validity through Sep 24, 2026; checked Jun 28, 2026 at 13:00 UTC.
The content indicators and 2 positive source findings support the current credential phishing classification.
ネットワークセキュリティインテリジェンス Registrar Integrity Alert
脅威対応 Pipeline
公開ブロックリスト登録状況
保存済みキャプチャ
ドメイン・インテリジェンス
技術的な詳細DNS、SSL SAN、タイムスタンプ
SHORTDOTゾーン · 公開証拠
.cfd
不正利用のために作られ、保護として売り戻される。
不正利用のために作られ、保護として売り戻される。
私たちの証拠アーカイブは、ShortDotが運営する7つのゾーンの全登録ドメインを追跡しています。レジストリの年間卸売収益を約1,260万ドルと推計しており、現在までに検証済みの正当な事業は一つも確認されていません。私たちの評価では、これらのゾーンはほぼ例外なく使い捨ての不正利用インフラとして機能し、その一方で同じ商業圏の企業が、そこで生じるゴミからブランドを守るサービスを販売しています。ShortDotは収益を得て、インターネットはゴミ捨て場を引き受けます。
ICANN OVERSIGHT
認定と RAA の背景
認定と RAA の背景
ICANNには支払いが済んだ。説明責任は届かなかった。
このgTLDでは、上記のレジストラはICANNとの契約に基づいて運営されています。ICANNは、登録、更新、移管に連動する年間手数料、変動手数料、および取引ベースの手数料を徴収します。
認定:収益化済み。説明責任:後ほどもう一度ご確認ください。
そして魔法が始まります。ICANNがRAA §3.18を書き、レジストラは自らの顧客基盤内の不正利用を自ら調査し、被害者は証拠を無償で提供する一方、各層は誰か別の者が動くのを待ちます。それで被害者が少しでも安全になった気がするなら、結構なことです――請求書は仕事を果たしたわけです。
Latest Classified Outcome 2026-08-06 04:01:50 UTC
使用技術 · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 信頼度 100%Express is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
expressjs.com 信頼度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 信頼度 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 信頼度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 信頼度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 信頼度 100%VirusTotalによる分析
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください