xrp2025[.]com
“Medium — Official XRP Giveaway — Brad Garlinghouse”
xrp2025.com — Conteúdo indisponível (HTTP 502). Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); 1 external blocklist match (Enkrypt); PhishDestroy score 89/100. Registrador: Beget.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
On July 24, 2026, analysts documented the domain xrp2025.com as an active component of a cryptocurrency giveaway scam targeting supporters of XRP. The site was registered on February 2, 2025 through Beget LLC and resolves to IP address 94.181.229.250, which belongs to AS41727 JSC "ER-Telecom Holding" in Russia. No TLS certificate is presented, and the domain uses the nameservers ns1.dedic.pro and ns2.dedic.pro. The page title returned by the server is "Medium — Official XRP Giveaway — Brad Garlinghouse", indicating a direct reference to the XRP ecosystem and its executive.
VirusTotal analysis recorded 13 detections out of 95 security vendors, and the domain appears on two external blocklists. Independent threat‑intel platforms have added the domain to one AlienVault OTX pulse, and both PhishDestroy and Enkrypt have listed it as blocked. Gridinsoft assigned a trust score of 0 out of 100, reinforcing the malicious assessment.
The site is currently offline, but the infrastructure remains observable and could be re‑activated. Defenders should immediately block the domain and its associated IP at perimeter and DNS layers, monitor for any related C2 traffic from the same ASN, and update internal detection rules to flag the exact page title. Continuous re‑scanning of the domain is advised in case it returns online, and any future variants should be compared against the observed nameserver and registrar patterns to accelerate identification.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo