lickedyou[.]xyz
“Connect Wallet”
lickedyou.xyz — Conteúdo indisponível. Representação da marca: Genericcrypto; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 2/93 (alphaMountain.ai, Forcepoint ThreatSeeker); URLScan malicious verdict; PhishDestroy score 56/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis as of 24 July 2026 indicates that the domain lickedyou.xyz was registered on 21 February 2026. The site hosts a page titled “Connect Wallet”, consistent with a crypto‑draining phishing campaign. Hosting is provided through Cloudflare, as the domain resolves to IP address 188.114.96.3, which belongs to ASN 13335 (Cloudflare, Inc.) located in the United States. The authoritative nameservers are blair.ns.cloudflare.com and theo.ns.cloudflare.com, and the TLS certificate presented is identified as “WE1”.
The domain has been flagged by PhishDestroy and appears on a single public blocklist. On VirusTotal, two of ninety‑three scanning engines returned a positive classification, reinforcing the suspicion of malicious activity. Independent reputation scoring from Gridinsoft rates the site at 0 out of 100, indicating an extremely low trust level. The current operational status is offline, suggesting that the phishing infrastructure has been taken down or is no longer serving content.
Evidence gaps remain regarding the specific phishing kit used, any observed payload delivery, and the extent of victim impact, as no additional forensic artifacts have been publicly disclosed. Defenders should continue to monitor the associated IP address and Cloudflare ASN for any re‑use, enforce URL filtering for the exact domain, and include it in threat‑intel feeds. Organizations that employ crypto‑wallet integrations should educate users about unsolicited “Connect Wallet” prompts and verify URLs before entering credentials. Because the domain is already listed on at least one blocklist and has a zero trust score, immediate blocking is recommended while awaiting further indicators of compromise.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo