worldlibfinancialeth[.]xyz
worldlibfinancialeth.xyz — Контент недоступний (HTTP 502). Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 7/93 (ChainPatrol, alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 71/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain worldlibfinancialeth.xyz was registered on 21 February 2026 and is currently marked as offline. Infrastructure analysis shows that the domain resolves to IP 104.21.112.1, which is hosted by Cloudflare (AS13335) in the United States. The TLS certificate presented is identified as WE1, indicating a standard Cloudflare‑issued certificate without additional validation. The page title returned by HTTP requests is the generic string “Just a moment…”, and no further content has been captured, leaving the exact phishing landing page unknown.
Threat intelligence feeds have flagged the domain as a crypto‑related scam. Seven of ninety‑three VirusTotal scanners have reported malicious indicators, and the domain appears on a single external blocklist. PhishDestroy has actively blocked the domain, confirming that at least one security vendor has taken remediation action. No additional public blocklists, Safe Browsing entries, or OTX tags were observed in the supplied data.
The available evidence points to a typical crypto phishing operation: a newly created domain, rapid deployment behind a reputable CDN, and a minimal page title that often precedes a redirect to a malicious payload. However, the lack of captured page content, URL paths, or payload samples limits the ability to attribute a specific campaign or enumerate victim targeting. Consequently, the precise phishing vector, credential‑harvesting method, and any associated malware remain uncertain.
Defenders should add worldlibfinancialeth.xyz to network and DNS blocklists, monitor outbound connections to its Cloudflare IP, and enforce TLS inspection to detect any concealed redirects. Continuous re‑scanning with multi‑vendor services is advised to capture evolving detections. Given the domain’s recent creation date and existing vendor flags, the risk posture is elevated, and proactive containment is recommended until further forensic details become available.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога