xaiquest[.]com
xaiquest.com 网络钓鱼与安全检查
“XAIQUEST Official Website Presale Get Up to 200% Bonus!”
xaiquest.com — 内容不可用 (HTTP 502). 品牌冒充:Genericcrypto; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 9/93 (ADMINUSLabs, CyRadar, ESET, Fortinet, G-Data); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 77/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain xaiquest.com shows a short‑lived infrastructure that was created on February 27, 2026 and is currently offline. The authoritative nameservers eric.ns.cloudflare.com and vita.ns.cloudflare.com resolve the domain to the IP address 188.114.97.3, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The domain was registered through NiceNIC International Group Co., Limited, a registrar known to host both legitimate and illicit registrations. No TLS certificate was observed, indicating the site served only HTTP traffic.
The page title retrieved during the brief investigation reads “XAIQUEST Official Website Presale Get Up to 200% Bonus!”, and the threat classification is identified as Brand Impersonation. VirusTotal scans recorded nine detections out of ninety‑three security vendors, demonstrating moderate consensus among scanners that the domain is malicious. Additionally, the domain appears on a single public blocklist and is explicitly blocked by the PhishDestroy service, reinforcing its classification as a phishing vector.
While the site’s full content has not been captured, the available evidence—registration timing, Cloudflare hosting, lack of encryption, page title, and multi‑vendor detections—supports an elevated risk rating. Defenders should add 188.114.97.3 to network blocklists, enforce DNS filtering for xaiquest.com, monitor for newly registered domains using the same registrar or similar naming patterns, and ensure email security gateways are updated to block communications that reference the observed page title or associated brand‑impersonation tactics. Continuous re‑scanning of the domain after any future re‑activation is advised to capture potential changes in payload or infrastructure.
网络安全情报 Registrar context
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-08 04:34:40 UTC
VirusTotal 分析
证据与外部报告
PD-20260227-D6506F Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。