aicapital[.]cyou
“The domain aicapital.cyou is powered by NicNames.com”
aicapital.cyou — 未验证. 诈骗类型:Crypto Drainer. 证据摘要: VirusTotal 13/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 89/100. 注册商: Nicnames.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies aicapital.cyou as a live crypto drainer domain under active threat investigation due to its recent deployment and suspicious infrastructure alignment. This domain is currently operational and engaging in malicious activities designed to deceive users into connecting crypto wallets, which may result in asset drainage or credential compromise. aicapital.cyou was registered through NicNames, Inc, a registrar often leveraged in bulk malicious domain creation campaigns, and is actively resolving to IP address 159.203.143.218 while utilizing a Let's Encrypt SSL certificate for added legitimacy. Despite zero detections on VirusTotal as of the latest scan, the domain has already been blocked by MetaMask and SEAL, indicating high-risk classification by multiple security platforms.
This domain exhibits multiple red flags indicative of crypto drainer infrastructure. aicapital.cyou was created on May 02, 2026, a recent timestamp suggesting opportunistic deployment aligned with current market events or trends. It has been flagged by 2 of 95 VirusTotal vendors and currently resides on two security blocklists, including industry-leading threat intelligence feeds. The domain's hosting IP at 159.203.143.218 shows no established trust score and has not been previously indexed in reputable service whitelists. While the page title indicates use of NicNames' hosting infrastructure, this alone does not mitigate risk, as NicNames has been repeatedly observed in abuse reports tied to fraudulent domain registrations. The absence of detections does not equate to safety; rather, it reflects the evasive nature of this threat and its likely targeting of cryptocurrency users under time-sensitive conditions.
As of this advisory, aicapital.cyou remains active and unmitigated by major browsers or DNS filters, posing a direct threat to individuals visiting the site. Crypto drainers like this exploit user urgency—such as fake token launches or urgent wallet connection prompts—to trick victims into signing malicious transactions. Users who interact with this domain risk wallet compromise, fund loss, and credential exposure. Immediate action is required: block this domain at the DNS or endpoint level, flag all associated IPs and SSL certificates, and update corporate blocklists. End users should be warned against visiting aicapital.cyou and encouraged to verify URLs via official channels. Further, enterprises should scan network logs for outbound connections to 159.203.143.218 and inspect any internal hosts that resolved this domain. This threat is ongoing, and proactive monitoring is essential to prevent compromise.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
SHORTDOT 域名区 · 公开证据
.cyou
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of aicapital.cyou · checked May 4, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。