Güvenlik raporuna geç
Checked 09.08.2026 Ref 5D825943

MALICIOUS — HIGH

oxidefai[.]com

4 of 91 security engines flagged the domain; the latest stored check returned HTTP 502.

65/100 evidence score · High
VirusTotal
4/91
Blocklists
No stored match
Kullanılabilirlik
İçerik kullanılamıyor · HTTP 502
Report / Add Evidence Appeal this listing
2026-03-24 21:29 UTCİçerik kullanılamıyor · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 4. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
Jump to section
Rapor özeti

oxidefai.com — İçerik kullanılamıyor (HTTP 502). Dolandırıcılık türü: Investment Scam. Kanıt özeti: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); URLQuery 1 det.; PhishDestroy score 65/100. Kayıt kuruluşu: Ultahost.

Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.

Evidence Digest

Ref 5D825943

oxidefai.com has a stored high classification with an evidence score of 65/100. 4 of 91 security engines flagged the domain. Registered 24 Mar 2026 via Ultahost, Inc., hosted on 212.224.107.10 (Ultahost, Inc., DE). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 24 Mar 2026.

Stored generated summary (templated)mistral · 24.03.2026

Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.

PhishDestroy identifies oxidefai.com as an active generic phishing domain impersonating AI Trading services, suspected to host a crypto drainer kit designed to siphon cryptocurrency assets. The page, titled OxideFAI – AI Trading, leverages a deceptive front-end built with Bootstrap, Material Design Lite, Leaflet, and particles.js, suggesting a polished but malicious interface. The backend operates on a Microsoft ASP.NET stack hosted via IIS on a Windows Server, with SSL provided by Let’s Encrypt, indicating an attempt to appear legitimate while concealing malicious intent.

Technical indicators reveal a highly evasive setup: oxidefai.com boasts a current VirusTotal detection score of 0/95, remains unflagged by Google Safe Browsing, and shows no presence on major blocklists despite its recent creation on September 16, 2025. The domain is registered through Ultahost, Inc. and resolves to IP address 212.224.107.10, which has not yet been widely blacklisted. This combination of fresh registration, low detection rates, and sophisticated front-end frameworks highlights a deliberate effort to evade early-stage detection mechanisms.

Currently, oxidefai.com remains active and under investigation, with no immediate takedown action reported. Users are advised to avoid interaction and verify any AI Trading-related links using PhishDestroy’s verification tools. While the immediate risk is classified as under investigation, the lack of current detections suggests potential for rapid escalation. Remaining risk hinges on further analysis and blocklist propagation—organizations should monitor for connections to 212.224.107.10 and update network defenses accordingly.

VirusTotal
VirusTotal
4 det.
URLQuery
URLQuery
1 det.
URLScan
URLScan
TLS sertifikası
Let's Encrypt
Yaş
5 mo
Gözlemlenen durum
İçerik kullanılamıyor 502
PhishDestroy
DestroyList
Listede
Reports Sent
1
Veri kapsamı12 recorded checks
VirusTotal 4 / 91 URLQuery 1 det. PhishStats checked — no match recorded OTX no community references CF Radarı scan completed URLScan capture saklanan rapor URLScan verdict Analiz tamamlandı DNS engellemeleri 14 kontrol edildi — engelleme yok TLS valid certificate, 84d WHOIS 5 mo old Ekran görüntüsü 3 captures · 3 sources Yönlendirme zinciri araştırılmadı

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Kullanılabilirlik
13/13
Sent Report Recorded
Stored sent-report record for registrar Ultahost, Inc., hosting provider, 4 abuse contacts
oxidefai.com@ultahost.comu-abuse@ultahost.comabuse@ultahost.comabuse@first-colo.net
24.03.2026

Genel Engelleme Listesi Durumu

Kaydedilen görüntü

Sayfa başlığı
OxideFAI – AI Trading
TLS sertifikası
Valid transport encryption · Düzenleyen Let's Encrypt · valid for 84 days

Etki Alanı Analizi

Alan adı
URLScan Verdict Analiz tamamlandı score 0 report ↗
Sunucu / ASN Microsoft-IIS/10.0 · AS214036 Ultahost, Inc.
IP itibarı abuse score 0/100 0 reports checked 14.07.2026
IP adresi 212.224.107.10 DE
Coğrafi konumDE Neu-Isenburg, DE
AS214036 · UltaHost Inc
KayıtOluşturuldu 24.03.2026 (137d)
HTTP Durumu502 Error
İlk erişilemezliğe kadar geçen süre 29 days
Neyi ölçüyoruz Depolanan ilk kötüye kullanım raporundan içeriğin kullanılamadığına dair ilk gözleme kadar geçen süre. Bu, nedeni belirlemez.
Her raporun içeriği Saklanan giden rapor kayıtları, satıcı kararları, kayıt verileri, barındırma ayrıntıları, sınıflandırmalar veya ekran görüntüleri gibi o sırada mevcut olan kanıtlara referans verebilir. Bu sayfa, teslim edilen yükün, alındığının, onaylandığının veya alıcının yaptığı eylemin tam olarak ne olduğu konusunda bir sonuç çıkarmaz.
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
İlk Kez Tespit Edildi24.03.2026
IoC Extractionscanned 29.07.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://oxidefai.com/
Ad sunucularıns2.oxidefai.com
TLS Fingerprint
TLS Observationvalid from 19.03.2026scanned 25.03.2026
Favicon Hash
Case ID
ICANN OVERSIGHT

Akreditasyon ve RAA bağlamı

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Hiçbir şey otomatik olarak gönderilmez.
Teknolojiler · 20 identified
Plesk
Windows Server
P
particles.js
Leaflet
Microsoft ASP.NET
Material Design Lite
Bootstrap
UI frameworks

Popular CSS framework for responsive, mobile-first web development.

I
IIS
Cloudflare
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
Unpkg

Fast CDN for everything on npm — serves raw files from npm packages.

Swiper
JavaScript libraries

Modern mobile touch slider with hardware-accelerated transitions.

SweetAlert2
Select2
J
jsDelivr
CDN

Free public CDN for open-source projects, serving files from npm and GitHub.

J
jQuery CDN

Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.

jQuery
JavaScript libraries

Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.

Google Tag Manager
Tag managers

Tag management system for deploying marketing and analytics tags.

tagmanager.google.com
Font Awesome

Icon font library.

cdnjs
Popper
Detected via Cloudflare Radar · Wappalyzer engine
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

4 / 91 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
alphaMountain.ai
CRDF
Gridinsoft
SOCRadar
Site Performans Analizi

Google PageSpeed Insights — mobile performance audit of oxidefai.com · checked Mar 24, 2026

59
Needs Work
Performance
FCP
1.96s
First Contentful Paint
LCP
10.79s
Largest Contentful Paint
CLS
0.01
Cumulative Layout Shift
TBT
445ms
Total Blocking Time
SI
4.99s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin
Bu Raporu YerleştirRead-only HTML widget
HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/oxidefai.com"
  title="PhishDestroy threat report for oxidefai.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Çok İçten Bir Teşekkür Mektubu

Hicivli taslak oluşturucu

Alıcı
Ücret bağlamı

Hicivli taslak. Ücret rakamları tahminidir; bu alan adına kesin olarak atfedildikleri iddia edilmez.