セキュリティレポートへ移動
⚠️
このドメインは悪意のあるものとして報告されています
検出を報告するセキュリティ エンジン: 6。 一致を報告する公開ブロックリスト: 2。 細心の注意を払ってください — 資格情報や個人情報を入力しないでください。
ドメインのセキュリティと脅威インテリジェンス

x-fire[.]icu

“Firelight – The Protection Layer for Digital Assets”

脅威の評決 クリティカル 100/100 証拠スコア
可用性 クローク済み · 到達可能 クローキングチェックを通じて監視される到達可能性
VirusTotal 検出数: 6/91 Spamhaus DBL: DBL_PHISH 保存されたブロックリストの一致: 2 詐欺タイプ: Crypto Drainer 最後に確認されたアクティブな状態
2026年4月27日 CDN

保存済みの検出

クローキング警告

クローキングの種類
redirect_split
クローキングスコア
5/6
スキャナー向けタイトルJust a moment...
訪問者向けタイトルFirelight – The Protection Layer for Digital Assets

証拠の概要

重要
Evidence score
100/100

PhishDestroy analysts have flagged x-fire.icu as an active cryptocurrency drainer domain under investigation. Security teams note the domain is not associated with a specific brand or drainer kit, making it a generic yet dangerous tool for wallet emptying campaigns. The threat actor leverages deceptive naming to impersonate legitimate services, posing a severe risk to users' digital assets through click-through or malicious links. Given the domain's youth—created on April 25, 2026—and its still-building detection history, the window for proactive blocking remains critical. This domain resolves to IP 172.67.161.98 and currently exhibits 0 detections per VirusTotal’s 95-engine scan. It was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, and secured via a Let’s Encrypt SSL certificate, enhancing its deception capabilities by enabling HTTPS traffic. The domain remains unlisted in Google Safe Browsing and has not yet been indexed on major threat blocklists, indicating an early-stage deployment likely intended for targeted phishing attacks. These technical indicators suggest a low-profile actor testing operational readiness. The domain is categorized as active with a risk level labeled as under_investigation. Security teams recommend immediate triage: identifying and blocking 172.67.161.98 at the network perimeter, inspecting DNS resolutions for x-fire.icu, and revoking any associated SSL certificates. While detection signatures catch up and blocklists mature, users are urged to verify URLs before interaction and disable auto-execution of wallet scripts in browsers. Remaining risk remains high due to the early stage of threat intelligence coverage. Users should treat any interaction with x-fire.icu as a potential credential or fund theft attempt and report observed activity to PhishDestroy for rapid analysis.

VirusTotal
VirusTotal
6 det.
TLS証明書
Let's Encrypt
年齢
4 mo
観測ステータス
クローク済み · 到達可能 HTTP 403
PhishDestroy
DestroyList
掲載あり

Data Coverage

VirusTotal 6 / 91 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references CFレーダー scan completed URLScan capture 保存されたレポート URLScan verdict 分析完了 DNSブロック 12 確認済み — ブロックなし TLS valid certificate, 87d WHOIS 4 mo old スクリーンショット 3 captures · 3 sources リダイレクトチェーン 調査されていない
ネットワークセキュリティインテリジェンスRegistrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

脅威対応 Pipeline

ディスカバリー
Checks
Reports
可用性
11/13

ブロックリストの確認範囲

監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月11日

監視対象の外部情報源 8 件 一致なし

保存済みの結果証拠

結果とテイクダウンの帰属

結果
protected
可用性
reachable_protected
原因
cloudflare_challenge
実行主体
Cloudflare
手段
challenge
確信度
85%
最初の観測
最新の観測

証拠の SHA-256 5d4d265ed0fb

検出タイムライン

  1. 可用性

    最初の保存値: 不明

    993d00c35140
  2. 可用性

    不明 → コンテンツ公開中

    b6dbb435e141
  3. 可用性

    コンテンツ公開中 → 保護

    bff35beb7ea8
  4. 可用性

    保護 → 不明

    9ab745633249
  5. 可用性

    不明 → 保護

    5d4d265ed0fb

コミュニティ報告

コミュニティの 1 人が報告・初回確認 2026年4月27日

保存済み報告
1
報告された固有 URL
1
承認1

保存済みキャプチャ

ページタイトル
Firelight – The Protection Layer for Digital Assets
TLS証明書
Valid transport encryption · 発行者 Let's Encrypt · valid for 87 days

ドメイン・インテリジェンス

ドメイン
URLScan Verdict 分析完了 score 0 report ↗
サーバー / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Edge-IP の評判はこのドメインに起因しません。
レジストラ NiceNIC RU(RU) PhishDestroy Investigation
不正利用連絡先abuse@nicenic.net
ICANNレジストリICANN公認レジストラ →
IPアドレス 172.67.161.98 CDN
地域CA Toronto, CA
ネットワークAS13335 · Cloudflare, Inc.
発信元 IP は CDN プロキシの背後に隠されています。エッジ アドレスのリバース IP の結果には、無関係なテナントが含まれています。発信元を見つけるには、パッシブ DNS または証明書の透明性データが必要です。
登録情報作成日 2026年4月27日 (105d)
HTTPステータス403 Forbidden
Elapsed Since First Report 36h
集計対象 Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: クローク済み · 到達可能.
各レポートの内容 保存された送信レポートの記録は、ベンダーの評決、登録データ、ホスティングの詳細、分類、スクリーンショットなど、その時点で入手可能な証拠を参照する場合があります。このページは、配信された正確なペイロード、受信者による受信、確認、またはアクションを推測するものではありません。
技術詳細DNS、TLS 名、タイムスタンプ
初確認2026年4月27日
Submitted URLhttp://x-fire.icu/
ネームサーバーkami.ns.cloudflare.com
TLS フィンガープリント
TLS 観測2026年4月25日 から有効2026年4月27日 にスキャン
SHORTDOTゾーン · 公開証拠 .icu

ShortDot zone evidence

The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.

ShortDot SA · Luxembourg 7ゾーン · ゾーン全体の証拠を毎日更新 ShortDot証拠リポジトリを開く
ICANN OVERSIGHT

認定と RAA の背景

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft 自動送信は一切行われません。

使用技術

高確信度で特定された技術:7 件

Framer Sites React Amazon Web Services HSTS Google Analytics Amazon SES HTTP/3
Cloudflare Radar
このドメインを報告する 証拠を提出し、他の人を守る手助けをしましょう

VirusTotalによる分析

6 / 91 セキュリティ ベンダーがこのドメインにフラグを立てました
View on VT
Last analyzed Previous stored snapshot: 2 detections
alphaMountain.ai
CRDF
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
SOCRadar
サイトパフォーマンス分析

Google PageSpeed Insights — mobile performance audit of x-fire.icu · checked Apr 27, 2026

64
Needs Work
Performance
FCP
3.35s
First Contentful Paint
LCP
5.68s
Largest Contentful Paint
CLS
0.002
Cumulative Layout Shift
TBT
254ms
Total Blocking Time
SI
5.31s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

このサイトによって何か影響を受けましたか?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。

ユーロポール
EU 加盟国の公式報告チャネルを見つける
National police directory
復旧を装った詐欺に注意! 犯罪者は、捜査員、弁護士、または回収業者を装い、被害者に再び連絡を取る可能性があります。 前払い料金を支払ったり、資格情報を共有したりしないでください。 回復詐欺について詳しくはこちら →

お住まいの地域の当局へ報告してください

サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。

97か国のディレクトリ
AI 支援ドラフト — インシデントの詳細は AI プロバイダーによって処理されます 自分で確認して送信する

任意のドメインを確認する

保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析

今すぐスキャン

フィッシングを報告する

不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう

レポート

リアルタイム脅威情報フィード

最近のフィッシングレポートと観察された可用性の変化

監視

最新情報を入手し、安全を確保しましょう

リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください

リアルタイム脅威情報フィード この掲載情報について異議を申し立てる

外部ツール

HTML · IFRAME

このレポートを埋め込む

この脅威情報を、ご自身のウェブサイトやブログで共有してください

embed.html
<iframe
  src="https://phishdestroy.io/ja/embed/domain/x-fire.icu"
  title="PhishDestroy threat report for x-fire.icu"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

たいへん心のこもった感謝状

風刺的な下書き生成ツール

宛先
手数料の背景

風刺的な下書きです。手数料額は推計であり、このドメインに正確に帰属すると主張するものではありません。