ag-token[.]xyz
Kanıt özeti
Analysis of the domain ag-token.xyz, first observed on June 10, 2026, indicates active malicious use consistent with generic phishing. The domain is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and is hosted on Cloudflare infrastructure, as evidenced by the nameservers celeste.ns.cloudflare.com and junade.ns.cloudflare.com and the presence of HTTP/3 support. DNS resolution points to IP address 188.114.96.3, which is geolocated to Canada and belongs to Cloudflare, Inc. The site serves a TLS certificate issued by Google Trust Services, providing a seemingly legitimate HTTPS connection that may increase victim trust. Malware and URL reputation services have flagged the domain; four of ninety‑five VirusTotal scanners reported it as malicious, and it appears on a single public blocklist. The phishing indicator is corroborated by inclusion in the PhishDestroy blocklist, confirming that at least one dedicated anti‑phishing service has taken remediation action. No additional intelligence such as page titles, brand impersonation, or specific payload details is currently available, limiting the depth of behavioral insight. Defenders should block network traffic to 188.114.96.3, add ag-token.xyz to local and upstream DNS deny lists, and monitor for related Cloudflare‑hosted domains that share the same nameserver set. Continuous re‑evaluation is recommended as further threat intelligence, such as additional vendor detections or content analysis, becomes available.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260720-3E6F50
Kanıtın tam metni
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler
2 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ag-token.xyz · checked Jul 20, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin