xvvchi.com — Контент недоступен (HTTP 502). Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); URLQuery 2 alerts; Spamhaus DBL_SPAM; 1 external blocklist match (ScamSniffer); PhishDestroy score 78/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Facts
PhishDestroy first observed xvvchi.com on May 5, 2026. The captured page title is “defi mining”. Stored page analysis classifies the content as credential phishing. Evidence score: 78/100 (critical).
4 independent sources recorded positive findings: VirusTotal, ScamSniffer, Spamhaus DBL, and URLQuery. VirusTotal recorded 6 detections among 91 engines: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar on Jul 12, 2026 at 23:28 UTC. ScamSniffer listed the hostname in the separate external-blocklist snapshot on Aug 9, 2026 at 10:20 UTC. Spamhaus DBL: DBL_SPAM on Jul 13, 2026 at 14:38 UTC. URLQuery recorded 2 threat-system alerts on May 5, 2026 at 03:17 UTC.
HTTP 502 was recorded on Aug 9, 2026 at 02:18 UTC; content was unavailable. Registration records for the domain list Gname.com Pte. Ltd. as the registrar and Apr 27, 2026 as the creation date. At collection time, the hostname resolved to 43.175.169.161 on AS139341 (ACE). The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery.
Охват данных12 recorded checks
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | www.trx-tron.net |
malicious | Sinkholed |
| DNS4EU | www.trx-tron.net |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 4 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% уверенностиjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиPopper is a positioning engine, its purpose is to calculate the position of an element to make it possible to position it near a given reference element.
popper.js.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of xvvchi.com · checked Jul 13, 2026
Доказательства и внешние отчетыIndependent lookups and source reports
PD-20260505-8084C8 Recipient: as139341_abuse@aceville.net Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.