trade-uni[.]xyz
“Suspected phishing site | Cloudflare”
trade-uni.xyz — Erro no servidor (HTTP 502). Representação da marca: Genericcloudflare. Resumo das evidências: VirusTotal 13/93 (alphaMountain.ai, Cluster25, CRDF, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 89/100. Registrador: NiceNIC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain trade-uni.xyz was registered on February 21 2026 through NiceNIC International Group Co., Limited and is served by Cloudflare nameservers malcolm.ns.cloudflare.com and sydney.ns.cloudflare.com. DNS resolution points to IP 188.114.96.3, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The site currently returns no SSL certificate, indicating that HTTPS was not provisioned before the host was taken offline. The HTTP response includes the page title “Suspected phishing site | Cloudflare”, a default block page displayed by Cloudflare when a domain is flagged for malicious activity. VirusTotal scans show that 13 of 93 security vendors have flagged the domain, demonstrating a moderate level of detection across independent engines.
AlienVault OTX lists the domain in one threat‑intelligence pulse, and PhishDestroy has added it to its blocklist, confirming that at least one dedicated anti‑phishing service treats the domain as hostile. Additionally, the domain appears on a separate security blocklist, bringing the total count of external listings to two. The available evidence points to a typical phishing infrastructure: rapid registration, use of a reputable CDN to hide the true origin, and reliance on Cloudflare’s default block page to signal abuse. No further content analysis is available because the site is offline and no SSL certificate or additional page metadata were captured. Consequently, the exact phishing lure or targeted brand cannot be confirmed at this time.
Defenders should block traffic to trade‑uni.xyz at the network perimeter and ensure that any client‑side security solutions reference the domain in their URL filtering or reputation lists. Monitoring for new DNS records or changes to the underlying IP address is recommended, as threat actors frequently shift hosting providers after takedown.
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-05 18:43:52 UTC
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo