xalurxojup[.]cyou
“Nowy projekt o nazwie "RocketBitPro" został uruchomiony. Oferuje on każdemu mieszkańcowi Polski moż…”
xalurxojup.cyou — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 20/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); PhishDestroy score 95/100. Регистратор: Namecheap.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain is flagged for hosting a targeted financial fraud operation under the guise of a cryptocurrency investment opportunity named RocketBitPro. Analysis indicates the threat type is a crypto asset drainer combined with credential theft, specifically designed to exploit Polish-speaking users by promising unrealistic returns of up to 90,000 PLN monthly. The scheme employs psychological manipulation through high-pressure claims of limited-time offers and fabricated success stories to coerce victims into transferring funds or disclosing wallet credentials. Infrastructure analysis reveals multiple high-risk indicators. The domain xalurxojup.cyou was registered on January 8, 2026, through Namecheap, exhibiting an anomalous future creation date that suggests domain spoofing or registry manipulation. It resolves to IP address 172.67.204.89, hosted on Cloudflare's network (AS13335), which is frequently leveraged by threat actors to obfuscate backend infrastructure. The domain appears on one security blocklist and is flagged by 20 out of 95 security vendors on VirusTotal, with detection labels including 'phishing,' 'fraudulent investment,' and 'crypto drainer.' The SSL certificate is classified as WE1, indicating a low-trust or potentially automated issuance process. Additional evidence includes its current offline status and prior blocking by PhishDestroy, a specialized anti-phishing system. Mitigation requires a multi-layered approach tailored to crypto asset protection. Users should immediately cease all interactions with the domain and any associated communication channels, including email or social media links referencing RocketBitPro. Financial institutions and crypto exchanges should monitor for transactions linked to the domain or IP 172.67.204.89, particularly those involving Polish users or PLN conversions. Organizations should update endpoint protection rules to block the domain, IP, and any derived indicators of compromise (IoCs), such as the page title fragment or SSL certificate thumbprint. Victims are advised to revoke access to any connected wallets, rotate credentials for all financial accounts, and report the incident to relevant cybercrime units, including local law enforcement and crypto fraud reporting platforms. Proactive measures include deploying DNS-based filtering to prevent resolution of the domain and educating users about the hallmarks of fraudulent investment schemes, such as guaranteed returns and urgency-driven calls to action.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ЗОНА SHORTDOT · ПУБЛИЧНЫЕ ДОКАЗАТЕЛЬСТВА
.cyou
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание