xsec[.]keplindomi[.]workers[.]dev
“Pegasus - Next-Generation Data Infrastructure”
The domain xsec.keplindomi.workers.dev is listed as an active generic phishing site with a specific focus on cryptocurrency drainage. The domain was registered on May 01 2026 through Cloudflare, Inc. and resolves to the IP address 188.114.97.3, which is hosted in Canada by Cloudflare’s network. HTTP requests return a 200 status code, and the site presents a TLS certificate issued by Let’s Encrypt (E8). Technical profiling shows the front‑end is built with Three.js and Tailwind CSS, and assets are served from cdnjs. The server enforces HTTP Strict Transport Security and negotiates HTTP/3 connections, indicating modern configuration. No custom nameserver records were identified, and the Gridinsoft trust score is 0 out of 100, reflecting a high‑risk assessment. The visible page title, “Pegasus – Next‑Generation Data Infrastructure,” is unrelated to the underlying activity and is likely used to lure victims. Intelligence classifies the operation as a “Crypto Drainer” scam, suggesting the site attempts to trick users into transferring cryptocurrency to addresses controlled by the adversary. The domain appears on one security blocklist and is already blocked by PhishDestroy, though VirusTotal currently shows zero detections. Defenders should add 188.114.97.3 and xsec.keplindomi.workers.dev to network deny lists and enable DNS sink‑holing for the domain. Monitoring of outbound traffic for attempted crypto‑wallet connections to unknown addresses is advised. Continuous re‑evaluation is required, as the threat actor may modify the payload or shift hosting while retaining the same domain fingerprint.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 10.08.2026
Технології
Виявлено 6 технологій із високою впевненістю
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of xsec.keplindomi.workers.dev · checked May 1, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога