MALICIOUS — CRITICAL
sklnbox.net — Cryptocurrency Drainer Detected & Blocked
sklnbox[.]
PhishDestroy identifies the domain sklnbox.net as an active cryptocurrency drainer kit, flagged by security vendors with an elevated risk level.
- VirusTotal
- 8/91
- Blocklists
- No stored match
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
sklnbox.net — Контент недоступний (HTTP 502). Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 8/91 (Fortinet, Webroot); Spamhaus DBL_PHISH; PhishDestroy score 74/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
PhishDestroy identifies the domain sklnbox.net as an active cryptocurrency drainer kit, flagged by security vendors with an elevated risk level. This domain is a recent addition to the threat landscape, created on April 24, 2026, and resolves to the IP address 188.114.97.3. The domain is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and secured with a Let’s Encrypt SSL certificate, which may lend it an air of legitimacy to unsuspecting users.
This domain exhibits multiple technical indicators of malicious intent. According to VirusTotal, 2 out of 95 security vendors flagged sklnbox.net as malicious, indicating a low but present detection rate among security tools. The domain was created on April 24, 2026, and is associated with the IP address 188.114.97.3. NICENIC INTERNATIONAL GROUP CO., LIMITED is listed as the registrar, and the domain is not currently flagged in Google Safe Browsing (GSB). Despite its recent creation, the domain has not yet been widely blocked, underscoring the need for proactive monitoring.
As of the latest analysis, sklnbox.net remains active and poses an elevated risk to potential victims. PhishDestroy recommends immediate action to block this domain at the network level and advises users to avoid interacting with any associated links or websites. While the current risk is elevated, the domain’s low VirusTotal detection rate suggests that threat intelligence sharing and updated blocklists are critical to mitigating its impact. Remaining risk is moderated by the domain’s recent creation but could escalate if the drainer kit gains traction among cybercriminals.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Обсяг даних13 recorded checks
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 04:21:09 UTC
Технології · 5 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіJavaScript library to animate elements on your page as you scroll.
michalsnik.github.io 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of sklnbox.net · checked May 1, 2026
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260501-B9315B Recipient: abuse@nicenic.net Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.