expeditionpics[.]xyz
“Expedition NFT Giveaway”
expeditionpics.xyz — Непроверенный. Сводка доказательств: VirusTotal 2/93 (SOCRadar, Trustwave); URLQuery 1 alert; PhishDestroy score 60/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
expeditionpics.xyz is flagged as an inactive malicious site that was observed hosting a page titled "Expedition NFT Giveaway". The page title, combined with the classification of the underlying phishing kit as an "Airdrop Scam", suggests the site was intended to lure victims with a fraudulent NFT airdrop promise. The domain was registered on 24 February 2026 through NiceNIC International Group Co., Limited and uses Cloudflare’s DNS service (dawn.ns.cloudflare.com, titan.ns.cloudflare.com). DNS resolution points to IP address 188.114.97.3, which belongs to AS13335 Cloudflare, Inc., located in the United States.
No TLS certificate was presented; the site operated without HTTPS. VirusTotal records show that two of ninety‑three scanning engines flagged the domain, indicating some detection of malicious behavior. The domain is listed on a single public blocklist, PhishDestroy, confirming that at least one security provider has taken mitigation action. As of the report date, the site is taken offline, and no live HTTP response is available for further content analysis.
Consequently, the exact page markup, form fields, or redirect behavior remain unknown. Defenders should add the domain to deny‑list rules, monitor for any re‑hosting on alternative IP ranges, and consider extending detection signatures to include similar "Expedition NFT Giveaway" page titles. Ongoing observation of Cloudflare‑hosted domains registered through the same registrar may help identify future campaigns that reuse the same infrastructure. The lack of SSL and the short lifespan of the domain are typical of fast‑flux or throwaway phishing operations, reinforcing the need for rapid blocklist updates.
Данные сетевой безопасности Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | expeditionpics.xyz |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-17 03:00:33 UTC
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260224-44DC4A Recipient: abuse@nicenic.net, abuse@gen.xyz, compliance@icann.org Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание