arcblink[.]xyz
“ArcPay”
arcblink.xyz — Контент недоступний. Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 4/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 88/100. Реєстратор: Porkbun.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, arcblink.xyz, is an active crypto drainer site designed to extract cryptocurrency wallet credentials through brand impersonation of ArcPay. The site remains operational as of the latest verification, presenting a high-risk threat to users interacting with its interface. Analysis indicates the domain is flagged by 4 of 95 security vendors on VirusTotal, with additional detections on three independent blocklists. Infrastructure analysis reveals registration through Porkbun LLC, resolution to IP address 69.46.46.23, and an SSL certificate issued by Let’s Encrypt (YE1). The page title explicitly displays "ArcPay," reinforcing the impersonation vector. No historical data suggests prior legitimate use, and the domain’s creation date aligns with recent phishing campaign patterns. Current status confirms the domain remains active, with no takedown or mitigation measures observed. Organizations and individuals are advised to implement immediate network-level blocking of 69.46.46.23 and arcblink.xyz. Users should verify wallet interactions via official ArcPay channels only, and security teams should monitor for credential theft attempts originating from this infrastructure. Proactive hunting for related domains registered under Porkbun LLC or resolving to the same IP range is recommended.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% впевненостіExpress is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
expressjs.com 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of arcblink.xyz · checked Jun 10, 2026
Докази та зовнішні звіти
PD-20260610-E5FCDB Recipient: abuse@porkbun.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога