lickedyou[.]xyz
“Connect Wallet”
lickedyou.xyz — 内容不可用. 品牌冒充:Genericcrypto; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 2/93 (alphaMountain.ai, Forcepoint ThreatSeeker); URLScan malicious verdict; PhishDestroy score 56/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis as of 24 July 2026 indicates that the domain lickedyou.xyz was registered on 21 February 2026. The site hosts a page titled “Connect Wallet”, consistent with a crypto‑draining phishing campaign. Hosting is provided through Cloudflare, as the domain resolves to IP address 188.114.96.3, which belongs to ASN 13335 (Cloudflare, Inc.) located in the United States. The authoritative nameservers are blair.ns.cloudflare.com and theo.ns.cloudflare.com, and the TLS certificate presented is identified as “WE1”.
The domain has been flagged by PhishDestroy and appears on a single public blocklist. On VirusTotal, two of ninety‑three scanning engines returned a positive classification, reinforcing the suspicion of malicious activity. Independent reputation scoring from Gridinsoft rates the site at 0 out of 100, indicating an extremely low trust level. The current operational status is offline, suggesting that the phishing infrastructure has been taken down or is no longer serving content.
Evidence gaps remain regarding the specific phishing kit used, any observed payload delivery, and the extent of victim impact, as no additional forensic artifacts have been publicly disclosed. Defenders should continue to monitor the associated IP address and Cloudflare ASN for any re‑use, enforce URL filtering for the exact domain, and include it in threat‑intel feeds. Organizations that employ crypto‑wallet integrations should educate users about unsolicited “Connect Wallet” prompts and verify URLs before entering credentials. Because the domain is already listed on at least one blocklist and has a zero trust score, immediate blocking is recommended while awaiting further indicators of compromise.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。