MALICIOUS — CRITICAL
cmepro[.]cc
Analysis of cmepro.cc shows a newly registered (April 28 2026) domain hosted on Cloudflare infrastructure (IP 172.67.209.30, located in Canada).
- VirusTotal
- 5/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- المحتوى غير متوفر · HTTP 503
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
cmepro.cc — المحتوى غير متوفر (HTTP 503). نوع الاحتيال: Fake Exchange. ملخص الأدلة: VirusTotal 5/91 (alphaMountain.ai, Forcepoint ThreatSeeker); URLQuery 1 det.; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
Analysis of cmepro.cc shows a newly registered (April 28 2026) domain hosted on Cloudflare infrastructure (IP 172.67.209.30, located in Canada). The site presents a valid SSL certificate issued by Google Trust Services under the WE1 root, indicating normal TLS termination. DNS resolution uses the Cloudflare nameservers carlos.ns.cloudflare.com and meilani.ns.cloudflare.com, and HTTP responses return a 301 redirect. The domain is currently active and appears on three security blocklists, confirming ongoing malicious use. The page title advertises “CME Group: A decentralized trading platform with low fees and high liquidity”, yet the threat profile classifies the site as a fake exchange impersonating an investment scam. Scamadviser assigns a trust score of 16/100, Gridinsoft reports 0/100, and VirusTotal flags the domain with 5 out of 95 security vendors detecting malicious behavior. Blocklist entries from PhishDestroy, MetaMask, and SEAL further corroborate its phishing intent. Infrastructure analysis reveals the use of Vue.js and HTTP/3 on top of Cloudflare’s edge network, a common stack for rapidly deployed phishing pages. The registrar Gname.com Pte. Ltd. is known for low‑cost registrations, and the lack of additional hosting clues limits attribution. The high risk rating reflects the combination of brand impersonation, low trust scores, and active blocklist presence. Defenders should block cmepro.cc at network perimeter and update endpoint and email filters to include the domain and its associated IP address. Continuous monitoring of DNS queries for the Cloudflare nameservers can help detect future pivots. Because the site mimics legitimate financial services, user education campaigns should highlight the discrepancy between the advertised CME Group branding and the low‑trust scores observed. Threat intel feeds should be refreshed to capture any new indicators tied to this infrastructure.
نطاق تغطية البيانات13 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of cmepro.cc · checked Apr 28, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260428-AB3E3B Recipient: complaint@gname.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.