0xmas[.]top
“522: Connection timed out”
0xmas.top — 未验证. 诈骗类型:Fake Airdrop. 证据摘要: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; PhishDestroy score 78/100. 注册商: 耐思尼克国际集团有限公司.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis indicates that the domain 0xmas.top was registered on December 23, 2025 through the registrar 耐思尼克国际集团有限公司. The domain resolves to the IP address 172.67.205.221, which belongs to AS13335 Cloudflare, Inc. and is geolocated to the United States. DNS resolution uses the Cloudflare authoritative nameservers brenna.ns.cloudflare.com and coby.ns.cloudflare.com, indicating that the infrastructure is fully proxied behind Cloudflare’s edge network. The site serves an HTTPS certificate issued by Google Trust Services under the WE1 label, confirming the use of a valid TLS certificate despite the malicious intent. HTTP requests receive a 301 redirect and the final page title reports “522: Connection timed out”, a Cloudflare error page that suggests the origin server is not responding.
Front‑end technology fingerprints include AngularJS, HTTP/3 support, HSTS enforcement, and Cloudflare Browser Insights, all of which are typical of modern abuse kits hosted on shared infrastructure. The observed kit is identified as an “Airdrop Scam”, a common cryptocurrency‑related lure that promises free token distributions in exchange for personal credentials. Reputation data shows that 0xmas.top is currently blocked by the PhishDestroy feed and appears on one additional security blocklist. VirusTotal has recorded six detections out of ninety‑three scanned engines, reinforcing the malicious classification. Independent scoring from Gridinsoft assigns a trust rating of 0 out of 100, indicating an extremely high risk posture.
Given the combination of a recent registration, Cloudflare‑proxied hosting, a valid TLS certificate, and multiple independent detections, the domain should be treated as a high‑confidence malicious indicator. Defenders should add 0xmas.top to network deny lists, enforce URL filtering to block HTTP and HTTPS connections, and monitor for any outbound requests to the associated IP address.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
所用技术 · 5 identified
TypeScript-based SPA framework maintained by Google.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of 0xmas.top · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。