xyuvrot[.]net
“СОСАЛ?”
证据摘要
PhishDestroy has identified the domain xyuvrot.net as a brand impersonation threat specifically targeting Coinbase users. This domain was designed to mimic the legitimate Coinbase platform, likely aiming to steal login credentials, financial information, or cryptocurrency assets. The page title observed was 'СОСАЛ?', which is a suspicious and potentially misleading string that does not match any legitimate Coinbase content. The presence of a drainer kit could not be confirmed from available data, but the domain's structure and purpose strongly suggest credential harvesting or financial fraud.
Technical indicators for xyuvrot.net paint a clear picture of its malicious nature. VirusTotal flagged the domain with a score of 4 out of 95 security vendors, indicating that multiple independent security engines have identified it as harmful. The domain was registered through Web Commerce Communications Limited dba WebNic.cc, a registrar sometimes associated with lower-quality or suspicious domains. Its IP address, 104.21.37.145, is linked to Cloudflare, which can be used to obscure the true hosting location. The domain was created on July 06, 2025, making it very recent at the time of analysis, and it appears on 2 security blocklists. The SSL certificate was issued by WE1, which is not a widely trusted certificate authority, further raising concerns. Google Safe Browsing (GSB) status was not explicitly provided but given the blocklist presence, it is likely flagged or suspicious.
As of the latest check, xyuvrot.net is offline, which is a positive development. This suggests that either the hosting provider or registrar has taken action to disable the domain, or the threat actor has taken it down voluntarily. However, users should remain vigilant as similar domains may reappear under different names or IP addresses. PhishDestroy recommends that anyone who may have interacted with this domain change their Coinbase passwords immediately, enable two-factor authentication, and monitor their accounts for unauthorized activity. Avoid clicking on links from unsolicited emails or messages claiming to be from Coinbase, and always verify the URL before entering sensitive information. The risk level remains elevated due to the targeted nature of this phishing campaign and the potential for financial loss.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控