xebodi[.]cfd
xebodi.cfd のフィッシング・安全性チェック
“Messenger”
xebodi.cfd — コンテンツが利用できません (HTTP 502). 証拠の概要: VT 15/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); URLQuery 2 alerts; URLScan no malicious verdict; GSB no flag; Spamhaus DBL_SPAM; BL 0; CF Radar malicious; PD 98/100. レジストラ: NiceNIC.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
PhishDestroy first observed xebodi.cfd on Jun 28, 2026. The captured page title is “Messenger”. Current evidence score: 98/100 (critical).
Positive findings are stored from 4 sources: VirusTotal, Spamhaus DBL, Cloudflare Radar, and URLQuery. VirusTotal recorded 15 detections among 91 engines: alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, LevelBlue, Lionic, Netcraft, Sophos, Webroot on Jun 29, 2026 at 02:00 UTC. Spamhaus DBL: DBL_SPAM on Jun 28, 2026 at 14:30 UTC. Cloudflare Radar classified the hostname as malicious and placed it in the phishing category; its verdict timestamp was not retained. URLQuery recorded 2 threat-system alerts on Jun 28, 2026 at 12:37 UTC. Non-positive and contextual checks: On Jun 28, 2026 at 12:10 UTC, AlienVault OTX listed 1 community pulse reference (not vendor detections); Google Safe Browsing returned no flag. The external blocklist snapshot contained no matches on Aug 7, 2026 at 22:20 UTC. URLScan completed without a malicious verdict (score 0) on Jul 29, 2026 at 03:02 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:37 UTC; content was unavailable. Latest classified outcome: registration hold observed; cause registrar client hold; mechanism client hold; observed actor NICENIC INTERNATIONAL GROUP CO., LIMITED on Aug 5, 2026 at 17:15 UTC. Registration records for the domain list NICENIC INTERNATIONAL GROUP CO., LIMITED as the registrar and Jun 24, 2026 as the creation date. Registration preceded first observation by 3 days. At collection time, the hostname resolved to 104.21.45.57 on AS13335 (CLOUDFLARENET - Cloudflare, Inc., US). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. DOM analysis on Jun 28, 2026 at 14:20 UTC returned 98/100. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery. TLS metadata lists Google Trust Services / WE1 as the certificate issuer with validity through Sep 22, 2026; checked Jun 28, 2026 at 13:00 UTC.
The content indicators and 4 positive source findings support the current phishing classification. The stored fields do not identify an impersonated brand or victim interaction.
ネットワークセキュリティインテリジェンス Registrar Integrity Alert
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | xebodi.cfd |
malicious | Sinkholed |
| OpenDNS | xebodi.cfd |
phishing | Phishing Block |
脅威対応 Pipeline
公開ブロックリスト登録状況
保存済みキャプチャ
ドメイン・インテリジェンス
技術的な詳細DNS、SSL SAN、タイムスタンプ
SHORTDOTゾーン · 公開証拠
.cfd
不正利用のために作られ、保護として売り戻される。
不正利用のために作られ、保護として売り戻される。
私たちの証拠アーカイブは、ShortDotが運営する7つのゾーンの全登録ドメインを追跡しています。レジストリの年間卸売収益を約1,260万ドルと推計しており、現在までに検証済みの正当な事業は一つも確認されていません。私たちの評価では、これらのゾーンはほぼ例外なく使い捨ての不正利用インフラとして機能し、その一方で同じ商業圏の企業が、そこで生じるゴミからブランドを守るサービスを販売しています。ShortDotは収益を得て、インターネットはゴミ捨て場を引き受けます。
ICANN OVERSIGHT
認定と RAA の背景
認定と RAA の背景
ICANNには支払いが済んだ。説明責任は届かなかった。
このgTLDでは、上記のレジストラはICANNとの契約に基づいて運営されています。ICANNは、登録、更新、移管に連動する年間手数料、変動手数料、および取引ベースの手数料を徴収します。
認定:収益化済み。説明責任:後ほどもう一度ご確認ください。
そして魔法が始まります。ICANNがRAA §3.18を書き、レジストラは自らの顧客基盤内の不正利用を自ら調査し、被害者は証拠を無償で提供する一方、各層は誰か別の者が動くのを待ちます。それで被害者が少しでも安全になった気がするなら、結構なことです――請求書は仕事を果たしたわけです。
Latest Classified Outcome 2026-08-05 19:15:29 UTC
使用技術 · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 信頼度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 信頼度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 信頼度 100%VirusTotalによる分析
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください