proposals-usdai[.]xyz
proposals-usdai.xyz — Контент недоступний. Тип шахрайства: Fake Exchange. Зведення доказів: VirusTotal 6/94 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 70/100. Реєстратор: PDR.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, proposals-usdai.xyz, operates as a crypto drainer phishing site designed to steal digital wallet credentials and drain cryptocurrency funds from victims. Analysis indicates the site mimics legitimate decentralized finance (DeFi) platforms, tricking users into connecting wallets or entering seed phrases under false pretenses, such as claiming to offer token swaps or airdrops. Once credentials are entered, the site executes unauthorized transactions, transferring assets to attacker-controlled wallets without user consent. The threat primarily targets users of popular wallets and DeFi services, exploiting trust in branded interfaces and urgency-driven offers. Infrastructure analysis reveals multiple red flags confirming the malicious nature of this domain. The domain was registered on April 7, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently associated with phishing and fraudulent domains. At the time of assessment, the domain resolved to the IP address 188.114.97.3 and was flagged by 6 out of 95 security vendors on VirusTotal, including detections for phishing and malicious activity. Additionally, the domain appeared on three security blocklists and was proactively blocked by multiple wallet security providers. A trust score of 0/100 from Gridinsoft further corroborates the high-risk classification of this infrastructure. Users who visited proposals-usdai.xyz or interacted with its content should take immediate action to mitigate potential losses. First, disconnect any wallets linked to the site by revoking permissions via the wallet’s connected apps or dApp browser settings. Next, transfer remaining funds to a new, secure wallet using a trusted device, as the original wallet may be compromised. Monitor transaction histories for unauthorized activity and report any suspicious transactions to the wallet provider or relevant blockchain explorers. If seed phrases or private keys were entered, consider the wallet fully compromised and avoid using it for future transactions. Finally, scan the device used to access the site for malware, as phishing pages may deploy additional payloads. Users are advised to enable multi-factor authentication on all accounts and verify domain authenticity before interacting with any financial or DeFi platforms.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криміналістичні дані
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of proposals-usdai.xyz · checked Jun 26, 2026
Докази та зовнішні звіти
PD-20260407-1D7252 Recipient: abuse@publicdomainregistry.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога