Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
user-apyx[.]xyz
Kanıt özeti
PhishDestroy identifies user-apyx.xyz as an active credential harvesting domain currently impersonating a generic login portal to steal user credentials. This domain was flagged by PhishDestroy’s automated pipeline under seed 2ad3ea and is categorized as a generic phishing domain designed to harvest login credentials from unsuspecting users. The infrastructure suggests a drainer kit deployment, likely targeting users through phishing emails or social engineering campaigns to capture credentials in real time.
This domain resolves to IP address 185.53.179.128 and was registered through Dynadot LLC on March 30, 2026. VirusTotal currently shows 3/95 detection engines flagging this domain, indicating it is not yet widely recognized as malicious. This low detection rate highlights the stealthy nature of the campaign and the need for proactive monitoring. The domain has not been flagged by Google Safe Browsing (GSB) and remains unlisted on major blocklists, further increasing its potential reach and effectiveness. The combination of a newly created domain, low detection, and absence from blocklists makes this a high-risk phishing vector.
As of the latest assessment, user-apyx.xyz remains active and under investigation. PhishDestroy has flagged this domain for immediate takedown and reputation management. Users are strongly advised to avoid visiting this domain and to report any suspicious emails or messages linked to it. While the domain is not yet widely blocked, organizations should update firewall rules and endpoint protections to include IP 185.53.179.128 and domain user-apyx.xyz. Remaining risk is assessed as high due to low detection and active infrastructure, with potential for rapid expansion if unchecked. Enhanced user awareness and network-level defenses are critical to mitigate exposure.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260402-BA7FDD- Yakalanan sayfa başlığı
- user-apyx.xyz
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | s.cdn-fileserver.com |
malicious | Sinkholed |
| DigiCert UltraDNS | l.cdn-fileserver.com |
malicious | Sinkholed |
| DNS4EU | user-apyx.xyz |
malicious | Sinkholed |
| DNS4EU | realtimesearchresults.com |
malicious | Sinkholed |
| Cloudflare DNS | realtimesearchresults.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin