MALICIOUS — HIGH
xcoinplatform[.]io
1 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 502.
- VirusTotal
- 1 detections
- Blocklists
- 2 · MetaMask, SEAL
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
xcoinplatform.io — Контент недоступний (HTTP 502). Уособлення бренду: Binance; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 1 detections (engine total unavailable) (Gridinsoft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: PDR.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Digest
xcoinplatform.io is classified high with an evidence score of 66/100. 1 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registration metadata recorded via PDR Ltd. d/b/a PublicDomainRegistry.com, hosted on 188.114.97.3 (Cloudflare, Inc., US). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture.
Stored generated summary (templated)cerebras · 25.07.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis of xcoinplatform.io shows a short‑lived infrastructure that aligns with a crypto‑focused phishing operation. The domain was registered on February 21, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and is currently taken offline. DNS resolution points to 188.114.97.3, an address owned by AS13335 Cloudflare, Inc., located in the United States. Both authoritative nameservers—martin.ns.cloudflare.com and nelci.ns.cloudflare.com—are Cloudflare services, indicating the attacker leveraged a reputable CDN to hide origin infrastructure.
The site presented a page title of "X Wallet," which matches the declared scam type of a crypto scam, yet no SSL certificate was observed, leaving the HTTPS handshake unavailable. VirusTotal recorded a single positive detection out of ninety‑five scanners, confirming at least one security vendor flagged the domain as malicious. The host appears on three independent security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, reinforcing its classification as a phishing vector targeting cryptocurrency users.
No additional HTTP response details, Safe Browsing verdicts, or content snapshots are available because the site is offline, leaving the exact payload and user‑interaction flow unknown. Defenders should treat the domain as hostile: block DNS resolution and network traffic to 188.114.97.3, add the domain and associated IP to endpoint and email filtering rules, and monitor for similar Cloudflare‑hosted domains that use wallet‑related page titles. Continuous observation of Cloudflare‑originated IP ranges for emerging crypto‑phishing campaigns is advised, as the attacker may redeploy the same infrastructure under a new domain.
Обсяг даних12 recorded checks
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.