xyuvrot[.]net
“СОСАЛ?”
Kanıt özeti
PhishDestroy has identified the domain xyuvrot.net as a brand impersonation threat specifically targeting Coinbase users. This domain was designed to mimic the legitimate Coinbase platform, likely aiming to steal login credentials, financial information, or cryptocurrency assets. The page title observed was 'СОСАЛ?', which is a suspicious and potentially misleading string that does not match any legitimate Coinbase content. The presence of a drainer kit could not be confirmed from available data, but the domain's structure and purpose strongly suggest credential harvesting or financial fraud.
Technical indicators for xyuvrot.net paint a clear picture of its malicious nature. VirusTotal flagged the domain with a score of 4 out of 95 security vendors, indicating that multiple independent security engines have identified it as harmful. The domain was registered through Web Commerce Communications Limited dba WebNic.cc, a registrar sometimes associated with lower-quality or suspicious domains. Its IP address, 104.21.37.145, is linked to Cloudflare, which can be used to obscure the true hosting location. The domain was created on July 06, 2025, making it very recent at the time of analysis, and it appears on 2 security blocklists. The SSL certificate was issued by WE1, which is not a widely trusted certificate authority, further raising concerns. Google Safe Browsing (GSB) status was not explicitly provided but given the blocklist presence, it is likely flagged or suspicious.
As of the latest check, xyuvrot.net is offline, which is a positive development. This suggests that either the hosting provider or registrar has taken action to disable the domain, or the threat actor has taken it down voluntarily. However, users should remain vigilant as similar domains may reappear under different names or IP addresses. PhishDestroy recommends that anyone who may have interacted with this domain change their Coinbase passwords immediately, enable two-factor authentication, and monitor their accounts for unauthorized activity. Avoid clicking on links from unsolicited emails or messages claiming to be from Coinbase, and always verify the URL before entering sensitive information. The risk level remains elevated due to the targeted nature of this phishing campaign and the potential for financial loss.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin