migrate-re[.]xyz
“reUSD Bridge Migration | Re”
migrate-re.xyz — 内容不可用. 证据摘要: VirusTotal 4 detections (engine total unavailable) (alphaMountain.ai, Gridinsoft, LevelBlue, Webroot); URLQuery 1 alert; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 74/100. 注册商: PDR.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies migrate-re.xyz as an active fake migration scam domain operating at elevated risk. PhishDestroy’s automated analysis confirms this site masquerades as a legitimate migration portal, luring users into exposing login credentials or payment details under false pretenses. The threat is not generic phishing—it specifically exploits migration urgency to deceive visitors into trusting a counterfeit service interface. This domain was flagged by ScamSniffer and appears on 1 security blocklist. VirusTotal analysis reveals 4 out of 95 participating security vendors rate this domain as malicious. The domain resolves to IP address 188.114.96.3 and uses a valid Let’s Encrypt SSL certificate, which may help it appear trustworthy at first glance. Registered through PDR Ltd. d/b/a PublicDomainRegistry.com, migrate-re.xyz was created on May 08, 2026, suggesting it is a very recent and rapidly deployed threat designed to target users during active migration periods. Technical indicators reinforce the elevated risk: the domain’s recent creation date and low detection count (4/95) indicate it is likely part of a new campaign still building reputation. While the SSL certificate adds superficial legitimacy, the use of a newly registered domain and association with a known blocklist strongly suggest malicious intent. The site’s infrastructure (IP 188.114.96.3) has been observed hosting multiple fraudulent services, increasing confidence in the malicious classification. To mitigate exposure to this fake migration scam, users should avoid clicking links from unsolicited emails or advertisements promoting migration services. Verify any migration URL by typing it manually or using a trusted bookmark. Organizations should update browser blocklists using feeds from ScamSniffer and other threat intelligence sources. Website operators monitoring network traffic should block access to 188.114.96.3 and inspect DNS logs for queries to migrate-re.xyz. If credentials were entered, revoke them immediately and enable multi-factor authentication where possible. Report the domain to your email provider or cybersecurity team to help disrupt the campaign.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | migrate-re.xyz |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of migrate-re.xyz · checked May 16, 2026
证据与外部报告
PD-20260516-82E770 Recipient: abuse@publicdomainregistry.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。