ebi-xyz[.]com
“Ebi xyz: First DEX with HOT Wallet Ebi.xyz exchange on Telegram”
ebi-xyz.com — Последний известный активный (HTTP 200). Олицетворение бренда: Solana; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Forcepoint ThreatSeeker); PhishDestroy score 100/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain ebi-xyz.com shows that it was registered on 25 September 2024 through NiceNIC International Group Co., Limited. The site serves content over HTTPS using a Let’s Encrypt certificate (R13) and resolves to the IPv4 address 185.149.120.107, which is announced by AS57724 (DDOS‑GUARD LTD) and geolocated to Russia. The web server identified is Nginx. The page title returned by the HTTP request is “Ebi xyz: First DEX with HOT Wallet Ebi.xyz exchange on Telegram”, and the domain is explicitly marked as impersonating the Solana brand. The domain appears on a single security blocklist and has been flagged by PhishDestroy. Reputation services assign a Scamadviser score of 1/100 and a Gridinsoft score of 0/100, both indicating extreme distrust. The site is currently live, returning HTTP 200. No detections are reported by VirusTotal (0/95), but the absence of signatures does not constitute evidence of safety. The content beyond the title has not been publicly disclosed, leaving the exact malicious payload or credential‑harvesting mechanisms unknown. The combination of a low‑reputation registrar, Russian‑based hosting, and a brand‑impersonation focus suggests a high likelihood of a cryptocurrency‑related scam, consistent with the listed scam type. Defenders should add ebi-xyz.com and its resolving IP 185.149.120.107 to block lists and intrusion‑prevention systems. Monitoring of DNS queries for the domain and of outbound traffic to the IP is advised. Users of Solana‑related services should be warned about the domain’s claim of a “first DEX with HOT Wallet” and instructed to verify official URLs. Continuous re‑scanning of the site on multi‑engine services is recommended to detect any future malicious payloads.
Сигналы безопасности
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-31 02:42:14 UTC
Технологии · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of ebi-xyz.com · checked Mar 2, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание