apps-ratex[.]xyz
“RateX | World’s 1st Leveraged Yield Exchange”
apps-ratex.xyz — Помилка сервера (HTTP 502). Тип шахрайства: Fake Exchange. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 83/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as a high-risk crypto drainer phishing site, designed to deceive users into connecting wallets to malicious smart contracts that siphon funds. The threat specifically targets cryptocurrency holders by impersonating RateX, a leveraged yield exchange platform, as evidenced by the page title 'RateX | World’s 1st Leveraged Yield Exchange.' Crypto drainers are particularly dangerous due to their irreversible financial impact, often leaving victims with empty wallets within minutes of interaction.
Analysis indicates the domain apps-ratex.xyz is hosted on IP address 104.21.65.72 and lacks an SSL certificate, a red flag for malicious infrastructure. It is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. The domain appears on two security blocklists (PhishDestroy and ScamSniffer) and is flagged by 4 out of 95 security vendors on VirusTotal. Infrastructure analysis reveals no legitimate association with the authentic RateX platform, further confirming its fraudulent nature. The domain remains active as of this report, increasing the urgency for mitigation.
To mitigate risks associated with this crypto drainer, users should immediately block the domain and IP address (104.21.65.72) at the network level. Wallet providers and exchanges should add the domain to their phishing filters and warn users attempting to interact with it. Cryptocurrency holders are advised to verify the authenticity of any platform before connecting wallets, using only official URLs and multi-factor authentication. If interaction with the domain has already occurred, users should revoke all connected wallet permissions and monitor transactions for unauthorized activity. Security teams should prioritize monitoring for similar domains registered under NICENIC INTERNATIONAL GROUP CO., LIMITED, as this registrar is linked to recurring phishing campaigns.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 02:56:45 UTC
Технології · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of apps-ratex.xyz · checked Jun 10, 2026
Докази та зовнішні звіти
PD-20260610-16E05E Recipient: abuse@gen.xyz Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога