events-chainlink[.]xyz
events-chainlink.xyz — Неперевірений. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Forcepoint ThreatSeeker, Gridinsoft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain events-chainlink.xyz was registered on April 15, 2026 through Dynadot LLC. It resolves to the Cloudflare‑owned address 172.67.221.253, located in Canada. The site is served with a Let’s Encrypt certificate (issuer E8) and is delegated to the Cloudflare name servers aldo.ns.cloudflare.com and arya.ns.cloudflare.com.
Infrastructure analysis shows the site returns HTTP 403 for direct requests, indicating that content is likely concealed behind authentication or redirection logic. The same IP address appears on three public security blocklists and is currently blocked by multiple anti‑phishing feeds, including PhishDestroy, MetaMask, and SEAL. VirusTotal scans have resulted in six of ninety‑five security vendors flagging the domain as malicious, and AlienVault OTX references the domain in one threat pulse.
The convergence of a newly created domain, a low Gridinsoft trust score of 0/100, and the presence on blocklists points to a high‑risk credential‑harvesting campaign that masquerades as Chainlink‑related services. While the exact landing pages cannot be retrieved due to the 403 response, the pattern of Cloudflare front‑end, Let’s Encrypt TLS, and rapid blocklisting aligns with known phishing kits that target cryptocurrency wallets and developer platforms. There is no public evidence of additional infrastructure such as command‑and‑control servers, but the domain’s active status suggests ongoing exploitation.
Defenders should block DNS resolution for events-chainlink.xyz at the network perimeter and add the associated IP address 172.67.221.253 to deny lists. Email gateways should quarantine any messages containing links to this domain, and security teams should monitor for credential submissions that reference Chainlink or related services. Continuous re‑scanning with multiple AV engines is advised to capture any changes in the payload, and incident response teams should treat any compromised credentials as potentially exposed.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога