Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
user-apyx[.]xyz
user-apyx.xyz — Não verificado. Tipo de golpe: Fake Exchange. Resumo das evidências: VirusTotal 3/94 (Forcepoint ThreatSeeker, Gridinsoft, Seclookup); URLQuery 5 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 71/100. Registrador: Dynadot.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies user-apyx.xyz as an active credential harvesting domain currently impersonating a generic login portal to steal user credentials. This domain was flagged by PhishDestroy’s automated pipeline under seed 2ad3ea and is categorized as a generic phishing domain designed to harvest login credentials from unsuspecting users. The infrastructure suggests a drainer kit deployment, likely targeting users through phishing emails or social engineering campaigns to capture credentials in real time.
This domain resolves to IP address 185.53.179.128 and was registered through Dynadot LLC on March 30, 2026. VirusTotal currently shows 3/95 detection engines flagging this domain, indicating it is not yet widely recognized as malicious. This low detection rate highlights the stealthy nature of the campaign and the need for proactive monitoring. The domain has not been flagged by Google Safe Browsing (GSB) and remains unlisted on major blocklists, further increasing its potential reach and effectiveness. The combination of a newly created domain, low detection, and absence from blocklists makes this a high-risk phishing vector.
As of the latest assessment, user-apyx.xyz remains active and under investigation. PhishDestroy has flagged this domain for immediate takedown and reputation management. Users are strongly advised to avoid visiting this domain and to report any suspicious emails or messages linked to it. While the domain is not yet widely blocked, organizations should update firewall rules and endpoint protections to include IP 185.53.179.128 and domain user-apyx.xyz. Remaining risk is assessed as high due to low detection and active infrastructure, with potential for rapid expansion if unchecked. Enhanced user awareness and network-level defenses are critical to mitigate exposure.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | s.cdn-fileserver.com |
malicious | Sinkholed |
| DigiCert UltraDNS | l.cdn-fileserver.com |
malicious | Sinkholed |
| DNS4EU | user-apyx.xyz |
malicious | Sinkholed |
| DNS4EU | realtimesearchresults.com |
malicious | Sinkholed |
| Cloudflare DNS | realtimesearchresults.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externos
PD-20260402-BA7FDD Recipient: abuse@dynadot.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo