exchange[.]mercuryo[.]io
“Mercuryo | Cryptocurrency Exchange Service Available 24/7”
exchange.mercuryo.io — لم يتم التحقق منها. انتحال العلامة التجارية: GMX; نوع الاحتيال: Fake Exchange. ملخص الأدلة: VirusTotal 2/91 (Chong Lua Dao, Gridinsoft); PhishDestroy score 61/100. مسجّل النطاق: GoDaddy.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of exchange.mercuryo.io indicates active brand impersonation targeting GMX, classified as a high-risk fake cryptocurrency exchange. The domain was registered on February 21, 2026, through GoDaddy.com, LLC, with an SSL certificate issued by GoDaddy.com, Inc. (Go Daddy Secure Certificate Authority - G2). It resolves to IPv6 address 2a05:d014:1b25:8366:9c62:441f:a8:e3a9, hosted on Amazon.com, Inc. infrastructure (AS16509, DE). Nameservers are AWS-based (ns-1161.awsdns-17.org, ns-1964.awsdns-53.co.uk, ns-483.awsdns-60.com, ns-873.awsdns), and the HTTP response status is 200, confirming the site is operational.
Detection data is limited: one of 93 security vendors on VirusTotal flags the domain, and it appears on a single blocklist (PhishDestroy). The page title, 'Mercuryo | Cryptocurrency Exchange Service Available 24/7,' aligns with the reported scam type (fake exchange). Trust scores are low: Gridinsoft rates it 1/100, while Scamadviser assigns 31/100. Technologies detected include Zendesk, HSTS, Google Analytics, and Forethought Solve, which may be used to lend legitimacy or track victims.
No evidence confirms whether this domain employs credential harvesting, wallet-draining scripts, or other attack vectors. Defenders should treat it as an active phishing resource impersonating GMX, block the domain and associated IP, and monitor for related infrastructure (e.g., AWS-hosted domains with similar naming patterns or SSL issuers). Further analysis of the site’s content and backend is required to determine exact payloads or redirection chains.
مؤشرات الأمان
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 4 identified
Customer support ticketing platform.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comتحليل VirusTotal
الأدلة المؤرشفة
تحليل إعدادات الموقع
الأدلة والتقارير الخارجية
“Classic payPal and advance payment scam. Screen is in czech but you can translate it. Overall it seems already just from the pictures and email structure”
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب