Güvenlik raporuna geç
⚠️
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 13. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
Etki alanı güvenliği ve tehdit istihbaratı

cyrexmodes[.]to

cyrexmodes.to için kimlik avı ve güvenlik kontrolü

“Cyrex | 🎮 Cyrex : A Modern Guide to Game Modifications”

Tehdit kararı Kritik 89/100 kanıt puanı
Kullanılabilirlik İçerik kullanılamıyor En son gözlemde içerik mevcut değildi
Risk sinyalleri
VirusTotal algılamaları: 13/91 Marka kimliğine bürünme: Across
13/91 VT 05.04.2026 06.04.2026'den beri kullanılamıyor Across Kimlik Bilgileri Kimlik Avı 2 Reports Sent 13h to unavailable RU RU
Rapor özeti

cyrexmodes.to — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Across; Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Forcepoint ThreatSeeker); PhishDestroy score 89/100. Kayıt kuruluşu: Government of Kingdom ….

Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.

Kanıt özeti
KRİTİK
Ref
861DA010
Puan
89/100

cyrexmodes.to has been flagged under active investigation for deploying a generic phishing drainer kit purporting to be a legitimate Cyrex Modes cryptocurrency wallet interface. The site mimics familiar crypto-branded UI cues to dupe victims into connecting wallets and signing malicious transactions. Security telemetry confirms an ongoing campaign aimed at cryptocurrency holders seeking discounted software or tooling. cyrexmodes.to was registered through the Government of the Kingdom of Tonga on March 28, 2026. It currently shows a VirusTotal detection ratio of 4 out of 95 engines as of seed 861da0, indicating zero detections despite active phishing behavior. The domain resolves to IP address 185.178.208.138 and operates under a Let's Encrypt SSL certificate, increasing perceived legitimacy. At present, this domain remains unlisted on Google Safe Browsing (GSB) and has not yet accumulated blocklist entries in major threat intelligence feeds, providing it a window of opportunity to attract victims. As of this report, the status of cyrexmodes.to is marked active and under active monitoring. Immediate user action includes blocking the domain at DNS and firewall levels, flagging the associated IP in network rules, and alerting cryptocurrency communities via trusted channels. Remaining risk remains HIGH due to zero AV detections and absence from public blocklists, meaning an expanding victim base is highly likely. Users are advised to avoid clicking links or downloading executables from this domain and to verify software sources through official channels only.

VirusTotal
VirusTotal
13 det.
URLScan
URLScan
TLS sertifikası
Let's Encrypt
Yaş
4 mo
Gözlemlenen durum
İçerik kullanılamıyor 502
PhishDestroy
DestroyList
Listede
Reports Sent
2
Veri kapsamı VirusTotal 13 / 91 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references CF Radarı no data URLScan capture saklanan rapor URLScan verdict Analiz tamamlandı DNS engellemeleri 12 kontrol edildi — engelleme yok TLS valid certificate, 84d WHOIS 4 mo old Ekran görüntüsü 3 captures · 3 sources Yönlendirme zinciri araştırılmadı

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Kullanılabilirlik
16/16
Initial Abuse Report (#1)
Sent to 2 abuse contacts at Government of Kingdom of Tonga with forensic evidence
abuse@tonic.tocompliance@icann.org
10.04.2026
ICANN Escalation #3
Escalation #3 sent to 2 recipients including ICANN Compliance — follow-up record after a previous report
abuse@tonic.tocompliance@icann.org
12.04.2026
2 Reports Filed
2 report records were stored over 119 days; current observed status: İçerik kullanılamıyor

Genel Engelleme Listesi Durumu

Kaydedilen görüntü

Etki Alanı Analizi

Alan adı
URLScan Verdict Analiz tamamlandı score 0 report ↗
Sunucu / ASN ddos-guard · AS57724 DDOS-GUARD LTD
IP itibarı abuse score 5/100 6 reports checked 14.07.2026
Kayıt kuruluşu Government of Kingdom …
IP adresi 185.178.208.138 RU
Coğrafi konumRU Rostov-on-Don, RU
AS57724 · Ddos-guard LTD
KayıtOluşturuldu 28.03.2026 (133d)
HTTP Durumu502 Error
İlk erişilemezliğe kadar geçen süre 13h
Neyi ölçüyoruz Depolanan ilk kötüye kullanım raporundan içeriğin kullanılamadığına dair ilk gözleme kadar geçen süre. Bu, nedeni belirlemez.
Minimum notice count 2 is the number of stored outgoing report records for this domain. It does not by itself prove acknowledgement or action by a recipient.
Her raporun içeriği Saklanan giden rapor kayıtları, satıcı kararları, kayıt verileri, barındırma ayrıntıları, sınıflandırmalar veya ekran görüntüleri gibi o sırada mevcut olan kanıtlara referans verebilir. Bu sayfa, teslim edilen yükün, alındığının, onaylandığının veya alıcının yaptığı eylemin tam olarak ne olduğu konusunda bir sonuç çıkarmaz.
ICANN RAA §3.18 The history below lists stored escalation records and timestamps. It does not by itself establish receipt, acknowledgement, compliance, or enforcement by any recipient.
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
İlk Kez Tespit Edildi05.04.2026
DOM Analysisanalyzed 29.07.2026score 56/1003 brand signals
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://cyrexmodes.to/
Ad sunucularıns1.ddos-guard.netns2.ddos-guard.net
TLS Fingerprint
TLS Observationvalid from 30.03.2026scanned 05.04.2026
Case ID
Sayfa başlığı
Cyrex | 🎮 Cyrex : A Modern Guide to Game Modifications
Impersonates
Across Outlook WhatsApp
TLS sertifikası
Valid transport encryption · Düzenleyen Let's Encrypt · valid for 84 days

Adli İstihbarat

Phishing Form Targets 1
feedback.php
Kötüye Kullanım Bildirimi Geçmişi · 2 stored reports over 3 days · click to expand
This timeline is built from stored outgoing report records. It documents timestamps and listed recipients, but does not by itself prove delivery, acknowledgement, or recipient action.
2 abuse reports filed over 119 days — latest observed status: İçerik kullanılamıyor
The records name Government of Kingdom of Tonga as a recipient or subject. ICANN Compliance appears in the recipient field for at least one record.
2
reports
119
days
ICANN CC
  1. Report #2 ICANN CC 125h still active Apr 10, 2026 · 21:46 UTC
    ESCALATION #2 (125h active): Phishing - cyrexmodes[.]to
    abuse@tonic.to compliance@icann.org
  2. Report #3 ICANN CC 175h still active Apr 12, 2026 · 23:46 UTC
    ESCALATION #3 (175h active): Phishing - cyrexmodes[.]to
    abuse@tonic.to compliance@icann.org
Record scope: the timeline documents outgoing records stored by PhishDestroy. Delivery, acknowledgement, and subsequent action require separate recipient or infrastructure evidence.
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

13 / 91 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed Previous stored snapshot: 4 detections
ADMINUSLabs
alphaMountain.ai
BitDefender
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
SOCRadar
Sophos
VIPRE
Webroot

Arşivlenmiş Kanıtlar

Wayback Machine Snapshot
Kanıt incelemesi için geçmişe ait bir anlık görüntü mevcuttur
View Archive
Site Performans Analizi

Google PageSpeed Insights — mobile performance audit of cyrexmodes.to · checked Apr 5, 2026

89
Needs Work
Performance
FCP
2.56s
First Contentful Paint
LCP
3.17s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
2.56s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Kanıtlar ve Dış Raporlar

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260405-3AAE17 Recipient: abuse@tonic.to
Page title stored with report: Cyrex | 🎮 Cyrex : A Modern Guide to Game Modifications
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 629.2 KB

Bu Siteden Etkilendiniz mi?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin

Herhangi Bir Alan Adını Kontrol Et

Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi

Şimdi Tara

Oltalama Olayını Bildir

Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun

Bildir

Canlı Tehdit Akışı

Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri

İzle

Gelişmelerden Haberdar Olun, Güvende Kalın

Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin

Canlı Tehdit Akışı Bu İlanı İtiraz Et
HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/cyrexmodes.to"
  title="PhishDestroy threat report for cyrexmodes.to"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>