skykkeo[.]xyz
“skykkeo.xyz”
skykkeo.xyz — Прикритий · доступний. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 93/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, skykkeo.xyz, is flagged as a high-risk phishing site specializing in crypto wallet credential harvesting. Analysis indicates the infrastructure is designed to mimic legitimate wallet interfaces, likely targeting users of decentralized finance platforms. No specific brand impersonation or drainer kit signatures have been confirmed at this time, though the domain structure and hosting patterns align with known phishing campaigns in the cryptocurrency space. Infrastructure analysis reveals the following technical indicators: the domain was registered on June 13, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with privacy-protected malicious registrations. It resolves to the IP address 188.114.97.3, hosted on AS13335 (Cloudflare, Inc.), a common proxy service used to obfuscate the true origin of phishing sites. The domain appears on one security blocklist, and VirusTotal reports a detection score of 1/95 security vendors. The SSL certificate is issued by Google Trust Services (WE1), which, while legitimate, provides no inherent trust for the domain's content. Google Safe Browsing (GSB) currently does not list this domain, though this may reflect a lag in detection rather than a clean status. As of the latest assessment, skykkeo.xyz remains active and unresolved, posing an ongoing threat to users. The domain's Cloudflare proxy complicates takedown efforts, and its recent registration suggests it may evade detection for an extended period. Users are advised to block the domain at the network level and avoid interacting with any content hosted on it. Organizations should monitor for connections to 188.114.97.3 and the AS13335 network range, as these may indicate compromised endpoints or successful phishing attempts. Given the domain's low detection rate, manual verification of wallet addresses and transaction requests is strongly recommended for users in the cryptocurrency ecosystem.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-18 02:47:15 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога