xrp-give[.]cc
“1 new message”
xrp-give.cc — 内容不可用 (HTTP 502). 品牌冒充:XRP; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 92/100. 注册商: CNOBIN INFORMATION TEC….
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of xrp-give.cc as of July 23, 2026 indicates that the domain is actively leveraged for brand impersonation targeting the cryptocurrency XRP. The domain was registered on 7 November 2025 through CNOBIN INFORMATION TECHNOLOGY LIMITED and resolves to the IP address 188.114.96.3, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. DNS resolution uses Cloudflare’s authoritative nameservers david.ns.cloudflare.com and hera.ns.cloudflare.com, suggesting the infrastructure is hosted behind Cloudflare’s CDN and WAF services. No TLS certificate is presented for the domain, meaning HTTPS connections are not available, which is consistent with a low‑trust configuration. The Gridinsoft trust score of 0 out of 100 further confirms the site’s malicious reputation.
Multiple detection mechanisms have flagged the domain. PhishDestroy has listed it as blocked, and it appears on at least one public security blocklist. VirusTotal reports that 14 of 95 scanned security vendors identified the domain as malicious, reinforcing the suspicion of phishing activity. The page title returned by HTTP requests is “1 new message,” which does not provide any legitimate context and may be used to entice victims. The current operational status is reported as offline, indicating that the site may have been taken down or is temporarily inaccessible, but the underlying infrastructure remains observable.
Given the evidence, defenders should continue to block DNS resolution for xrp-give.cc at the network perimeter and add the associated IP address 188.114.96.3 to any deny lists, keeping in mind that the IP belongs to a shared Cloudflare range and may host other unrelated services. Monitoring of the domain’s registration renewal and any re‑appearance of active web content is advised. Organizations that hold XRP assets should educate users about unsolicited messages claiming to originate from XRP‑related services and reinforce the use of official channels only.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。