x2lan[.]it
“x2lan.it”
Resumo das evidências
Analysis of the domain x2lan.it was performed on 24 July 2026. The domain was registered on 21 February 2026 through DESARROLLO COMERCIAL CAPITAL ONE TRADER SL and uses the authoritative name servers ns1.park‑my‑domain.net and ns2.park‑my‑domain.net. DNS resolution points to the IPv4 address 199.59.243.228, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in the United States. An HTTPS service is reachable; the presented certificate is classified as E7. An HTTP GET request returns status code 200 and the page title reported by the scanner is “x2lan.it”.
VirusTotal records indicate that two of ninety‑three participating vendors flagged the domain as malicious, confirming a detection signal. The domain is listed on two public blocklists, PhishDestroy and ScamSniffer, both of which categorize it as a generic phishing site. The risk rating assigned by the reporting system is elevated, and the current operational status is offline, suggesting that the malicious infrastructure may have been taken down or is no longer serving content. Evidence confirms the existence of a phishing‑related payload, but the specific content of the hosted page has not been disclosed in the available intelligence.
Consequently, the exact phishing lure, credential‑capture mechanisms, or target brand remain unknown. The limited number of vendor detections and blocklist listings indicate that the campaign may be in an early stage or employing a low‑profile hosting arrangement. Defenders should continue to monitor the IP address 199.59.243.228 for any re‑use, enforce blocklist updates that include PhishDestroy and ScamSniffer entries, and consider adding the domain to internal deny lists while awaiting further forensic collection. Additionally, analysts should request a full content capture from archival services to determine the precise phishing vector and assess any potential impact on users.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
9 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo