xtbtoken.com has been identified as an active phishing domain, with evidence drawn from multiple threat intelligence sources as of July 28, 2026. The domain was registered on July 23, 2026 through Realtime Register B.V. and is configured with nameservers a.share-dns.com, a11.share-dns.com, b.share-dns.net, and b11.share-dns.net. DNS resolution places the domain at IP address 137.220.205.157. The domain currently appears on one security blocklist and is actively blocked by the PhishDestroy service, signifying recognition by at least one anti-phishing vendor.
VirusTotal records indicate that the domain has been scanned by 91 vendors, but none currently flag it; however, this lack of detections is not evidence of safety, as phishing sites frequently evade automated scanners and detection lags are common. There is no information available regarding the site's content, targeted brand, or scam type, and the precise nature of its phishing activity is still under investigation. No SSL certificate or HTTP response details are present, and there is no additional intelligence about hosting provider, ASN, or geographic location. The domain remains active and operational, warranting continued monitoring.
Defenders should treat xtbtoken.com as a high-risk asset, given its presence on a blocklist and active blocking status. Immediate network-level blocking and monitoring for traffic to 137.220.205.157 is recommended. Further investigation into associated infrastructure and related domains is advised to determine the full scope of the threat. Exact content and tactics used by the site are not yet analyzed, so caution is advised until further intelligence is obtained.