kalyxen[.]io
“KALYXEN — The Unified DeFi Protocol”
kalyxen.io — 隐形 · 可达. 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); URLQuery 3 alerts; cloaking observed; PhishDestroy score 86/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain kalyxen.io is currently flagged as a high‑risk crypto‑scam phishing site. Infrastructure analysis shows the domain resolves to IP 216.150.1.1, which is hosted in the United States and belongs to ASN 16509, the Amazon.com network. Registration is handled by a CDN provider, and the authoritative name servers (clara.ns.cloudflare.com, nicolas.ns.cloudflare.com) are consistent with that service. A TLS certificate is present, issued by a public certificate authority, and the site responds with an HTTP 307 redirect. The page title returned by the server reads "KALYXEN — The Unified DeFi Protocol," indicating the attacker is attempting to impersonate a decentralized finance platform. VirusTotal reports that 2 of 94 security vendors have flagged the domain, and the Gridinsoft trust score is 0 / 100, reflecting a lack of trust. The domain is listed on at least one public blocklist and is already blocked by a phishing‑mitigation service. Although the exact malicious payload or credential‑harvesting page has not been captured, the combination of a crypto‑scam classification, active status, and confirmed redirection behavior suggests the site is being used to lure victims into disclosing private keys or sending funds. Defenders should immediately block the domain and its hosting IP at network perimeters, incorporate the indicator into endpoint detection rules, and monitor for any related traffic patterns. Continuous re‑evaluation is advised, as additional detection data may emerge.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。