vvvchecker[.]com
“X. It’s what’s happening / X”
Detecção armazenada
Alerta de cloaking
- Tipo de cloaking
bot_redirect_safe- Pontuação de cloaking
- 4/6
Resumo das evidências
PhishDestroy has identified vvvchecker.com as a dangerous phishing site that tries to steal your X (formerly Twitter) login credentials. The page title reads exactly like the official X login page: “X. It’s what’s happening / X,” tricking visitors into thinking they are on the legitimate platform. This is a classic credential harvesting attack, and anyone who enters their username and password on this site risks having their account compromised.
Our investigation uncovered several red flags. VirusTotal shows that 3 out of 95 security vendors flagged this domain as malicious, while the site itself is protected by a Let’s Encrypt SSL certificate (E7), which ironically gives it a false sense of security. The domain was registered on April 14, 2026, through Realtime Register B.V., and resolves to IP address 104.21.13.109. Currently, the site has been taken offline, but similar clones can reappear. It already appears on three security blocklists, confirming its malicious intent.
If you visited vvvchecker.com and entered your X credentials, change your password immediately and enable two-factor authentication. Also revoke any app permissions you may have granted. Even though the site is offline now, your data may have been captured. Stay alert for suspicious login attempts and consider using a password manager to avoid reusing passwords across sites.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | vvvchecker.com |
malicious | Sinkholed |
| Quad9 DNS | vvvchecker.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo