xfernobb[.]shop
“XfernoBB – Creative Freelancer Portfolio | Designer & Developer”
xfernobb.shop — Контент недоступний (HTTP 502). Уособлення бренду: Discord; Тип шахрайства: E Commerce Scam. Зведення доказів: VirusTotal 2/94 (alphaMountain.ai, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: Hostinger.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies xfernobb.shop as an active generic phishing domain leveraging crypto wallet impersonation tactics to facilitate wallet draining operations. This domain poses an elevated risk due to its active exploitation and multi-vector blocklist coverage. The infrastructure supports low-cost, high-reward credential harvesting paired with cryptocurrency theft through fake transaction interfaces. The seed identifier 3951be confirms the uniqueness of this campaign within tracking systems. This domain resolves to IP address 93.127.192.58 and utilizes a legitimate Let's Encrypt SSL certificate to enhance credibility. VirusTotal analysis indicates minimal vendor detection at 1/95 security vendors, suggesting either recent deployment or use of evasion techniques. Security blocklist coverage reaches critical mass with appearances on 2 separate threat intelligence platforms. MetaMask and SEAL security systems have already implemented blocking mechanisms against this domain. The registrar information and exact creation date remain unverified in available intelligence, though the active status and recent detection patterns suggest a recently established infrastructure. Current status shows this domain remains operational despite immediate detection by security vendors and browser-based protection systems. Immediate response actions should include network-level blocking at the firewall or DNS level using the domain and associated IP address. Users who may have interacted with this domain should immediately revoke any connected wallet permissions and transfer remaining assets to new, isolated wallets. Residual risk remains elevated due to the domain's ability to bypass some detection mechanisms, requiring continuous monitoring and threat intelligence updates. Organizations should implement additional monitoring for similar domains and consider deploying advanced behavioral analytics to detect wallet draining attempts in real-time.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криміналістичні дані
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of xfernobb.shop · checked Apr 8, 2026
Докази та зовнішні звіти
PD-20260408-4CF155 Recipient: report@abuseradar.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога