MALICIOUS — CRITICAL
skaxo[.]com
PhishDestroy identifies skaxo.com (seed b20b87) as an active generic phishing domain deploying a wallet-drainer kit targeting cryptocurrency users.
- VirusTotal
- 17/91
- Blocklists
- 2 · MetaMask, SEAL
- sẵn có
- Hoạt động được biết đến lần cuối · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 2 outgoing records; the latest is dated . The recorded recipient is abuse@trustname.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
skaxo.com — Hoạt động được biết đến lần cuối (HTTP 200). Mạo danh thương hiệu: Genericcrypto; Loại lừa đảo: Brand Impersonation. Tóm tắt bằng chứng: VirusTotal 17/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Nhà đăng ký: Fewmoretaps OU d/b/a T….
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
Evidence Analysis
PhishDestroy identifies skaxo.com (seed b20b87) as an active generic phishing domain deploying a wallet-drainer kit targeting cryptocurrency users. Domain registration is intentionally recent—15 April 2026—suggesting an opportunistic campaign rather than long-term infrastructure. No exact brand impersonation is confirmed in open-source feeds, but the drainer’s modus operandi typically mimics popular wallet interfaces to trick users into connecting malicious addresses and signing transfers. The kit automatically drains balances via crafted transaction signatures once the victim grants permissions, making it a high-impact threat with irreversible consequences. Technical indicators are precise: VirusTotal currently shows 0/95 detections; the domain resolves to IPv4 104.21.16.117 via Cloudflare, is registered through Fewmoretaps OU d/b/a Trustname.com, and is protected by a Let’s Encrypt SSL certificate. Creation date is 15 April 2026, and Google Safe Browsing has not yet blacklisted the page. Public blocklists record zero prior entries, indicating the domain is in initial deployment and still largely under the radar of automated defenses. Current status is active with risk level under_investigation; no takedown has been effected at this time. Security teams should block 104.21.16.117 at the firewall and DNS sinkhole skaxo.com immediately. Users are advised to revoke any wallet permissions granted to skaxo.com via blockchain explorers, rotate private keys if necessary, and report the domain to PhishDestroy for rapid ingestion into community blocklists. Remaining risk is elevated due to low VT coverage and absence on GSB; mitigation hinges on swift signature and network-layer blocking.
Phạm vi dữ liệu12 recorded checks
Tình báo an ninh mạng Registrar context
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Bản chụp đã lưu
Thông tin về tên miền
Chi tiết kỹ thuậtDNS, SAN trong SSL, dấu thời gian
ICANN OVERSIGHT
Bối cảnh công nhận và RAA
Bối cảnh công nhận và RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Lịch sử báo cáo lạm dụng · 2 stored reports over 3 days · click to expand
-
Report #2 ICANN CC 90h still active Apr 26, 2026 · 17:26 UTCESCALATION #2 (90h active): Phishing - skaxo[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 138h still active Apr 28, 2026 · 18:21 UTCESCALATION #3 (138h active): Phishing - skaxo[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
Phân tích của VirusTotal
Bằng chứng lưu trữ
Phân tích hiệu suất trang
Google PageSpeed Insights — mobile performance audit of skaxo.com · checked Apr 22, 2026
Bằng chứng và các báo cáo bên ngoàiIndependent lookups and source reports
PD-20260422-485615 Recipient: abuse@trustname.com Victim safety and official reportingImmediate actions and verified reporting channels
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.