md[.]payxie[.]cc
md.payxie.cc — Não verificado. Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 5/91 (Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar, Webroot); PhishDestroy score 78/100. Registrador: Gname.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies md.payxie.cc as a fraudulent payment portal designed to mimic the legitimate PayXie financial service. This domain operates as a credential-harvesting phishing site, specifically targeting users attempting to log in or complete transactions. No known drainer kit signatures were detected, but the site’s structure closely resembles common fake payment gateways used to steal login details and financial data. This domain was flagged by 4 out of 95 security vendors on VirusTotal, indicating moderate detection but clear malicious intent. It resolves to the IP address 104.21.17.85, a Cloudflare-protected endpoint that obscures the true origin of the attack. The registrar remains undisclosed, and domain creation records are not publicly available. Google Safe Browsing has not yet listed the domain, but it appears on at least one third-party blocklist. No SSL certificate irregularities were observed, which is common in phishing sites leveraging Cloudflare’s free certificates. As of the latest scan (seed f8caee), md.payxie.cc has been taken offline, likely due to hosting provider intervention or the attacker’s decision to abandon the campaign. While the domain is no longer active, users who visited the site should immediately change their PayXie credentials and monitor their accounts for unauthorized transactions. The remaining risk is elevated for individuals who entered sensitive information before the takedown. Security teams are advised to block the domain and IP in corporate networks to prevent accidental access if the site resurfaces under a new configuration.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo