Перейти до звіту про безпеку
⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 8. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Безпека домену та аналіз загроз

hxyhxy[.]sbs

“imToken | Ethereum & Bitcoin Wallet”

Загрозливий вердикт Критичний 74/100 оцінка доказів
Доступність Контент недоступний Вміст був недоступний під час останнього спостереження
Виявлення VirusTotal: 8/94 Уособлення бренду: Ethereum
19.04.2026 Ethereum 1 Report Sent
Огляд звіту

hxyhxy.sbs — Контент недоступний. Уособлення бренду: Ethereum; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 8/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Fortinet); PhishDestroy score 74/100. Реєстратор: Global Domain Group.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Зведення доказів
КРИТИЧНИЙ
Посилання
A96AC543
Оцінка
74/100

PhishDestroy identifies the domain hxyhxy.sbs as an active credential phishing threat designed to harvest user login credentials under false pretenses. The site currently remains online and operational as of evaluation, posing a direct and measurable risk to individuals and organizations that may encounter it through email campaigns, social media links, or fraudulent advertisements. While the exact impersonated brand or service has not yet been confirmed through open-source intelligence, the site’s structure and metadata indicate a high likelihood of masquerading as a legitimate login portal to deceive visitors into surrendering sensitive authentication details. Immediate avoidance is strongly advised. This domain—registered on August 21, 2025, through Global Domain Group LLC—was detected resolving to IP address 67.215.241.243 and secured with an SSL certificate issued by TrustAsia Technologies, Inc. As of this analysis, VirusTotal shows zero detections across 95 scanning vendors, highlighting a window of opportunity for threat actors to exploit unprotected traffic before widespread blacklisting occurs. The domain has not yet appeared on major threat intelligence blocklists, suggesting it may be newly operational or carefully segmented to evade early detection systems. The combination of a recent creation date, low detection coverage, and active infrastructure signals a potentially high-risk phishing operation with evolving tactics. Given the absence of current blocklist inclusion and low antivirus coverage, hxyhxy.sbs represents an unchecked phishing threat that could rapidly expand its reach. Users are advised to avoid visiting the domain and report any encounters to relevant security teams using the provided IP and domain indicators. Organizations should consider proactive blocking of 67.215.241.243 and hxyhxy.sbs at network and DNS levels, while conducting heightened phishing awareness training focused on newly registered domains with suspicious SSL certificates. Continuous monitoring through threat intelligence feeds is recommended to detect any shifts in infrastructure or campaign expansion. The domain remains under active investigation by PhishDestroy’s anti-phishing team.

VirusTotal
VirusTotal
8 det.
URLScan
URLScan
Сертифікат TLS
TrustAsia Technologies, Inc.
Вік
4 mo
Зафіксований статус
Контент недоступний
PhishDestroy
DestroyList
У списку
Reports Sent
1
Обсяг даних VirusTotal 8 / 94 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture збережений звіт URLScan verdict висновок недоступний Блокування DNS 12 перевірено — блокувань немає TLS valid certificate, 82d WHOIS 4 mo old Знімок екрана 3 captures · 3 sources Ланцюжок перенаправлень не досліджено

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
12/12
Sent Report Recorded
Stored sent-report record for registrar Global Domain Group LLC, hosting provider, 2 abuse contacts
abuse@globaldomaingroup.comreportabuse@racknerd.com
19.04.2026

Статус у публічних блоклистах

Збережений знімок

Заголовок сторінки
imToken | Ethereum & Bitcoin Wallet
Impersonates
Across Discord Ethereum Ton
Сертифікат TLS
Valid transport encryption · Виданий TrustAsia Technologies, Inc. · valid for 82 days

Аналітика доменів

Домен
Сервер / ASN nginx · AS36352 HostPapa
Репутація IP abuse score 0/100 0 reports checked 13.07.2026
Реєстратор Global Domain Group US(US)
IP-адреса 67.215.241.243 US
ГеолокаціяUS Los Angeles, US
МережаAS36352 · RackNerd LLC
Зворотний пошук IPviewdns.info → rapiddns.io →
РеєстраціяСтворено 19.04.2026 (122d)
Час до першої недоступності 3 days
Що ми враховуємо Час, що минув від першого збереженого звіту про порушення до першого спостереження, що вміст був недоступний. Це не встановлює причину.
Що містить кожен звіт Збережені записи вихідних звітів можуть посилатися на докази, доступні на той час, наприклад вердикти постачальників, реєстраційні дані, деталі хостингу, класифікації або знімки екрана. Ця сторінка не визначає точного доставленого корисного навантаження, квитанції, підтвердження чи дії одержувача.
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено19.04.2026
DOM Analysisanalyzed 29.07.2026score 63/1004 brand signals
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttps://hxyhxy.sbs/
Сервери іменconrad.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 12.04.2026scanned 19.04.2026
Case ID
ЗОНА SHORTDOT · ПУБЛІЧНІ ДОКАЗИ .sbs

ShortDot zone evidence

The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.

ShortDot SA · Luxembourg 7 зон · повні дані зон оновлюються щодня Відкрити репозиторій доказів ShortDot
ICANN OVERSIGHT

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.
Технології · 8 identified
Node.js
Programming languages

JavaScript runtime built on Chrome V8 engine for server-side development.

Ant Design
Nginx
Web servers Reverse proxies

High-performance HTTP server and reverse proxy, known for stability and low resource usage.

Express
scrollreveal
Help Scout
HSTS
Безпека

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

B
Baidu Analytics (百度统计)
Detected via Cloudflare Radar · Wappalyzer engine
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

8 / 94 постачальників безпеки позначили цей домен
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
BitDefender
CyRadar
Fortinet
G-Data
«Касперський»
Sophos
Аналіз продуктивності сайту

Google PageSpeed Insights — mobile performance audit of hxyhxy.sbs · checked Apr 19, 2026

69
Needs Work
Performance
FCP
1.38s
First Contentful Paint
LCP
6.68s
Largest Contentful Paint
CLS
0.148
Cumulative Layout Shift
TBT
127ms
Total Blocking Time
SI
2.56s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Докази та зовнішні звіти

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260419-CAB78D Recipient: abuse@globaldomaingroup.com
Page title stored with report: imToken | Ethereum & Bitcoin Wallet
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 57.0 KB

Чи вплинув на вас цей сайт?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно

Перевірити будь-який домен

Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування

Сканувати зараз

Повідомити про фішинг

Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту

Повідомити

Потокова стрічка про загрози

Останні звіти про фішинг і помічені зміни доступності

Відстежувати

Будьте в курсі подій, дбайте про свою безпеку

Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога

Потокова стрічка про загрози Оскаржити це оголошення
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/hxyhxy.sbs"
  title="PhishDestroy threat report for hxyhxy.sbs"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Дуже щирий лист-подяка

Генератор сатиричних чернеток

Одержувач
Контекст зборів

Це сатирична чернетка. Суми зборів є оцінками; ми не стверджуємо, що вони точно стосуються цього домену.