bitxchain[.]uk
“BitXchain - Trading for everyone”
证据摘要
Analysis of the domain bitxchain.uk, observed as offline as of 23 July 2026, indicates a targeted brand‑impersonation campaign aimed at users of the Aave platform. The site was registered through Porkbun LLC on 23 December 2025 and resolves to IP 66.45.244.235, which belongs to AS19318 Interserver, Inc, located in the United States. The domain uses the nameservers dns1400a.trouble‑free.net and dns1400b.trouble‑free.net, both commonly associated with disposable hosting services. No TLS certificate is presented, leaving the site accessible only via HTTP.
The page title returned from the now‑taken‑down site reads "BitXchain - Trading for everyone," which does not reference Aave but the domain name and title suggest an attempt to lure cryptocurrency traders. Security‑vendor scans on VirusTotal recorded six detections out of ninety‑three scanners, confirming malicious intent despite the relatively low detection ratio. The domain appears on a single external blocklist and is actively blocked by PhishDestroy, indicating that at least one security feed has flagged the infrastructure. Gridinsoft assigned a trust score of 0 / 100, reinforcing the assessment of a low‑reputation host.
Given the limited public visibility, the exact payload or credential‑capture mechanism remains unknown; no forensic capture of the landing page content has been published. Defenders should continue to block the IP address 66.45.244.235 and the domain bitxchain.uk at DNS and proxy layers, monitor for any re‑hosting attempts under related subdomains, and update endpoint protection rules to include the observed VirusTotal signatures. Organizations that employ Aave services should educate users about the absence of a legitimate "BitXchain" offering and advise against interacting with unsolicited links referencing this domain.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控