memecoinscommunity[.]xyz
“Un instant…”
memecoinscommunity.xyz — Неперевірений. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 5/94 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 69/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, memecoinscommunity.xyz, is identified as a crypto credential theft operation targeting users of cryptocurrency platforms. Analysis confirms the domain is currently offline, though prior activity suggests it was designed to harvest login credentials and private keys from unsuspecting victims under the guise of a community or investment opportunity. No specific brand impersonation has been confirmed, but the domain name leverages the popularity of meme coins to appear legitimate. Infrastructure analysis reveals the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on April 04, 2026, and resolves to the IP address 104.21.35.177. It appears on one security blocklist and is flagged by 5 of 95 security vendors on VirusTotal. The domain is also recorded in one AlienVault OTX threat intelligence pulse, and Gridinsoft assigns it a trust score of 0/100. Additional evidence includes its inclusion in PhishDestroy's blocklist, further corroborating its malicious nature. The domain's current offline status does not eliminate the risk, as threat actors frequently reactivate infrastructure or repurpose it for future campaigns. Organizations and individuals are advised to proactively block the domain and its associated IP address at the network perimeter. End users should be educated on recognizing credential theft tactics, particularly those targeting cryptocurrency holders. Security teams are recommended to monitor for any resurgence of this domain or related infrastructure, and to correlate logs for prior connections to 104.21.35.177. If credentials were entered on this domain, immediate password resets and wallet key rotations are critical to mitigate potential compromise.
Розвіддані з мережевої безпеки Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | memecoinscommunity.xyz |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-20 03:08:34 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260404-226225 Recipient: abuse@nicenic.net, abuse@gen.xyz Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога