emaartoken[.]xyz
“Emaar Launching Coin (EMAAR) — Residents Airdrop”
emaartoken.xyz — Непроверенный. Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 17/93 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); URLQuery 3 alerts; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, emaartoken.xyz, is identified as a brand impersonation threat specifically targeting OKX, a cryptocurrency exchange platform. The site presents itself as an airdrop campaign titled 'Emaar Launching Coin (EMAAR) — Residents Airdrop,' falsely associating with the legitimate Emaar brand to deceive users into divulging sensitive credentials or transferring assets. The domain is currently offline, but prior activity indicates a deliberate attempt to exploit trust in established brands for financial fraud. Analysis of technical indicators reveals the domain was registered through NiceNIC International Group Co., Limited on February 21, 2026, an unusually future-dated creation that may suggest registry manipulation or data obfuscation. It resolves to IP address 172.67.166.128, hosted on AS13335 Cloudflare, Inc., a common infrastructure choice for threat actors due to its anonymization capabilities. The domain appears on one security blocklist and is flagged by 17 of 95 security vendors on VirusTotal, including detection as a phishing or fraudulent site. The SSL certificate, issued by Google Trust Services (WE1), provides a veneer of legitimacy while failing to mitigate the underlying malicious intent. Infrastructure analysis further confirms the domain's association with Cloudflare, which, while not inherently malicious, is frequently leveraged to obscure hosting origins and evade takedown efforts. The domain's current offline status suggests either a temporary suspension due to enforcement actions or a strategic withdrawal by the threat actor to avoid further detection. However, the infrastructure remains a latent risk, as the domain could be reactivated or repurposed for future campaigns. Organizations and individuals are advised to block the domain and its associated IP (172.67.166.128) at the network level, including DNS and firewall rules. Users who interacted with the domain should assume credential compromise and initiate password resets for any accounts accessed during the exposure window. Monitoring for related domains registered through NiceNIC or resolving to Cloudflare IPs may help preemptively identify similar threats. Given the elevated risk level, security teams should prioritize reviewing logs for connections to this domain or its IP, particularly in environments where cryptocurrency transactions are common.
Данные сетевой безопасности Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | emaartoken.xyz |
malicious | Sinkholed |
| Quad9 DNS | emaartoken.xyz |
malicious | Sinkholed |
| DNS4EU | emaartoken.xyz |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-17 03:00:17 UTC
Технологии · 20 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comGoogle's bot-challenge service. On phishing sites, used to appear legitimate and filter out automated scanners.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
User-behavior analytics: heatmaps, session recordings, on-site surveys.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comPerformance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260214-0805FE Recipient: abuse@nicenic.net Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание