hub-guild[.]xyz
“KaijuKingz”
Kaydedilmiş tespit
Gizleme uyarısı
- Gizleme türü
content_divergence- Gizleme puanı
- 1/6
Kanıt özeti
PhishDestroy identifies hub-guild.xyz as an active crypto drainer with an elevated risk level. This domain is designed to steal cryptocurrency by tricking users into connecting their wallets to fraudulent smart contracts. The site mimics legitimate platforms, such as Guild.xyz, to exploit user trust and facilitate unauthorized fund transfers. Users who interact with this domain risk losing their digital assets to malicious actors who exploit wallet connection vulnerabilities. This domain exhibits multiple red flags consistent with fraudulent activity. SSL certificate issued by Let's Encrypt obscures its malicious nature, as phishers often use legitimate certificates to appear trustworthy. The domain was created on April 04, 2026, a suspiciously recent date suggesting opportunistic registration. It resolves to IP 172.67.144.143, a hosting address associated with previous malicious campaigns. VirusTotal analysis confirms detection by only 4 out of 95 security vendors, indicating poor coverage and high evasion potential. The domain is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar with a history of lax oversight on fraudulent domains. Additionally, hub-guild.xyz appears on three prominent blocklists, including those maintained by MetaMask, SEAL, and OISD, reinforcing its malicious classification. These technical indicators collectively confirm a high-risk threat actor with sophisticated evasion techniques. Mitigation for this crypto drainer threat requires immediate action from users and organizations. Never connect your cryptocurrency wallet to any website claiming to be Guild.xyz or similar platforms without verifying the official domain through multiple trusted sources. Use PhishDestroy to confirm domain legitimacy before interacting, as this tool cross-references active blocklists, SSL certificates, and threat intelligence feeds. If you have already connected your wallet, revoke suspicious smart contract permissions immediately using tools like Revoke.cash or similar wallet security features. Report this domain to your antivirus provider, wallet security teams, and relevant cybersecurity platforms to help disrupt ongoing campaigns. Always enable multi-factor authentication on wallets and use hardware wallets for high-value transactions to minimize exposure to drainer scripts.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Kaydedilmiş sonuç kanıtı
Sonuç ve kaldırma ilişkilendirmesi
- Sonuç
held- Erişilebilirlik
unreachable- Neden
registrar_client_hold- Aktör
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mekanizma
client_hold- Güven
- 95%
- İlk gözlem
- Son gözlem
Tahmini erişilememe
Erişilemezliğe kadar geçen süre: 0 hKanıt SHA-256 914b2fbfb0ba
Tespit zaman çizelgesi
-
Erişilebilirlik
İlk kayıtlı değer: DNS etkin değil
f93a11f87e4d -
Erişilebilirlik
DNS etkin değil → Bilinmiyor
b2864caa19de -
Erişilebilirlik
Bilinmiyor → DNS etkin değil
9474cbfb38b3 -
Erişilebilirlik
DNS etkin değil → Bekletiliyor
0429841a8ad2 -
Erişilebilirlik
Bekletiliyor → DNS etkin değil
f52d526b76a1 -
Erişilebilirlik
DNS etkin değil → Bilinmiyor
a4206ce6b3b5 -
Erişilebilirlik
Bilinmiyor → Bekletiliyor
d211da5db489 -
Erişilebilirlik
Bekletiliyor → Bilinmiyor
00235151a40d -
Erişilebilirlik
Bilinmiyor → DNS etkin değil
6dfe9145995c -
Erişilebilirlik
DNS etkin değil → Bilinmiyor
8540688960c9
Tümünü göster (7)
-
Erişilebilirlik
Bilinmiyor → DNS etkin değil
d0b7046e8c2f -
Erişilebilirlik
DNS etkin değil → Bilinmiyor
a1130da42fc8 -
Erişilebilirlik
Bilinmiyor → DNS etkin değil
92f667ff6e00 -
Erişilebilirlik
DNS etkin değil → Bilinmiyor
0c507e30a4ef -
Erişilebilirlik
Bilinmiyor → DNS etkin değil
9eda8dc3b7e8 -
Erişilebilirlik
DNS etkin değil → Bilinmiyor
dea4e3455a68 -
Erişilebilirlik
Bilinmiyor → Bekletiliyor
914b2fbfb0ba
Topluluk raporları
2 topluluk üyesi tarafından bildirildi; ilk görülme 07.04.2026
- Kayıtlı raporlar
- 2
- Bildirilen benzersiz URL’ler
- 1
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Adli İstihbarat
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of hub-guild.xyz · checked Apr 8, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin