xgram[.]my
“Buy and Sell Crypto online — Exchange to xgram.my”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
Analysis of xgram.my indicates this domain was actively used as a fraudulent cryptocurrency exchange platform. The domain, registered on July 29, 2025, through Porkbun LLC, resolved to a German-hosted IP address (62.60.226.213) under AS214351 (FEMO IT SOLUTIONS LIMITED). At the time of assessment, the site was offline, but its page title, 'Buy and Sell Crypto online — Exchange to xgram.my,' explicitly suggests it targeted users seeking crypto trading services. No SSL certificate was present, increasing exposure to interception risks.
Security vendors have widely flagged xgram.my: it appears on four blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura. AlienVault OTX records show the domain in 15 threat intelligence pulses, while Gridinsoft assigns a trust score of 0/100. Sixteen of 95 security vendors on VirusTotal detect the domain as malicious. The domain's nameservers remain active under Porkbun (curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, salvador.ns.porkbun.com), though the site itself is no longer resolving.
Defenders should treat xgram.my as confirmed malicious infrastructure. While the exact scale of victim interaction remains unclear, the domain's registration age, detection volume, and absence of encryption support high-risk classification. Network-level blocking is recommended for all endpoints, and security teams should monitor for related domains under the same registrar or hosting provider. Further investigation into associated IPs and certificates may reveal additional linked infrastructure.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
7 izlenen harici kaynak Eşleşme yok
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Topluluk raporları
1 topluluk üyesi tarafından bildirildi; ilk görülme 18.11.2025
- Kayıtlı raporlar
- 1
- Bildirilen benzersiz URL’ler
- 1
Topluluk istihbaratı
1 topluluk raporu
KategoriPHISHING
Detection Summary The Anti-Phishing Volunteers & Associates Security Incident Response System has flagged this as a domain threat, classified as phishing attack against several brands. Threat detected at 2025-12-06T22:51:03.293Z. Targeted Brands SimpleSwap Uniswap Raydium Dualcoi
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin