lexoindex-de[.]net
lexoindex-de.net — Контент недоступний. Уособлення бренду: Genericcloudflare. Зведення доказів: VirusTotal 10/93 (ADMINUSLabs, alphaMountain.ai, CRDF, CyRadar, ESET); URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 80/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
lexoindex-de.net was registered on 24 February 2026. Within weeks the domain began appearing in multiple security blocklists and was subsequently taken offline. VirusTotal records indicate that ten of ninety‑three scanning engines flagged the domain as malicious, suggesting a detection confidence that exceeds baseline noise. The site was served over HTTPS using a certificate identified only as “E8”, and the Gridinsoft trust score assigned a value of 0 out of 100, reflecting a complete lack of trust.
Hosting analysis shows the domain resolved to IP address 188.114.97.3, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The IP itself is shared across many unrelated services, but the association with Cloudflare does not mitigate the observed malicious indicators. The domain is listed on three public blocklists and is explicitly blocked by the PhishDestroy, MetaMask, and SEAL filtering services, reinforcing the conclusion that it was used for phishing‑related activity. At the time of reporting (24 July 2026) the domain is offline, and no HTTP response body or page title has been captured, leaving the exact phishing payload or targeted brand undefined.
The limited evidence therefore points to a short‑lived, high‑risk phishing infrastructure that was quickly disrupted. Defenders should continue to block the host IP, add lexoindex‑de.net to internal deny lists, and monitor for re‑registration or similar aliases that resolve to the same Cloudflare IP range. Ongoing threat‑intel feeds should be consulted for any resurgence, and any future DNS queries for the domain should be logged for correlation with credential‑theft attempts.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога