lynx-buyback[.]xyz
“soluna vs SHARK - LynxHL Voting”
lynx-buyback.xyz — İçerik kullanılamıyor (HTTP 502). Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 5/93 (alphaMountain.ai, Gridinsoft, Seclookup, SOCRadar, URLQuery); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 70/100.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain lynx-buyback.xyz was registered on 21 February 2026 and is currently listed as offline. DNS resolution points to the IPv4 address 185.95.159.71, which belongs to AS209101 (Vendetta Inc.) and resolves to a hosting location in the Netherlands. The site presented a page titled “soluna vs SHARK – LynxHL Voting”, and its SSL certificate is identified as version R13. Intelligence indicates that the operation impersonates the Twitter brand and is classified as a crypto‑scam, consistent with the “Crypto Scam” label in the data set.
The domain appears on three independent security blocklists and has been actively blocked by the PhishDestroy, MetaMask, and SEAL filtering systems. VirusTotal analysis recorded five positive detections out of ninety‑three scanners, confirming that a subset of malware and phishing engines recognize the domain as malicious. The registration details, hosting ASN, and blocklist presence collectively suggest a purposeful campaign targeting cryptocurrency‑related transactions while leveraging the Twitter brand for credibility. However, the absence of a live HTTP response limits the ability to inspect the exact payload, user‑interaction flow, or any embedded malicious binaries.
Consequently, the full scope of the malicious content, including potential wallet‑drain techniques or credential‑harvesting forms, remains undetermined. Defensive teams should continue to enforce blocklist rules for lynx-buyback.xyz, monitor outbound connections to 185.95.159.71, and incorporate the domain into URL‑filtering policies. Additional sandboxing of any retrieved content, if the site reappears, would allow verification of the specific crypto‑draining mechanisms and support attribution efforts. Ongoing observation of related registrants and the AS209101 network is recommended to detect future iterations of the campaign.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin