biddsxrpl[.]com
biddsxrpl.com 피싱 및 보안 점검
“Bidds XRPL Anniversary - Community NFT Airdrop”
biddsxrpl.com — 콘텐츠를 사용할 수 없음 (HTTP 502). 브랜드 사칭: Across; 사기 유형: Fake Airdrop. 증거 요약: VirusTotal 3/94 (Fortinet, Google Safebrowsing, SOCRadar); Google Safe Browsing flagged; Spamhaus DBL_PHISH; PhishDestroy score 80/100. 등록기관: NiceNIC.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies biddsxrpl.com as an active cryptocurrency-themed phishing domain currently under investigation. The site mimics legitimate crypto platforms to harvest wallet credentials and seed phrases under the guise of a fake airdrop or promotional campaign. This represents a targeted social-engineering effort against users familiar with XRP Ledger (XRPL) and related blockchain ecosystems. Given the domain’s recent registration and limited detection coverage, defenders should treat this as a high-priority threat until further IOCs are validated.
This domain was flagged by Google Safe Browsing for SOCIAL_ENGINEERING and currently shows 3 out of 95 VirusTotal detections. It resolves to IP address 104.21.60.126 and was registered on April 05, 2026 via NICENIC INTERNATIONAL GROUP CO., LIMITED using a Let’s Encrypt SSL certificate. The combination of a newly created domain, clean VirusTotal score, and presence on a major blocklist suggests an early-stage campaign likely leveraging low-cost infrastructure to evade immediate detection. Trust scores remain neutral to low due to the domain’s infancy and lack of historical reputation.
Organizations and individuals should immediately block biddsxrpl.com at the DNS and firewall levels. Users should be warned not to interact with any “XRPL airdrop” or “giveaway” pages linked from social media, ads, or unsolicited emails. Enable wallet software to flag unknown contract interactions and verify all transaction requests offline. Report any incidents involving wallet compromise or exposed seed phrases to incident response teams with IOCs including the domain and IP. Monitor internal DNS logs for queries to biddsxrpl.com and inspect HTTP(S) traffic for requests containing wallet addresses or mnemonic patterns.
네트워크 보안 인텔리전스 Registrar context
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 03:46:48 UTC
포렌식 인텔리전스
VirusTotal 분석
증거 및 외부 보고서
PD-20260411-45F1E9 Recipient: abuse@nicenic.net 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.