primexa[.]cc
فحص التصيد والأمان للنطاق primexa.cc
“Primexa: Most Popular Online Crypto Casino Based on Blockchain”
primexa.cc — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Genericcrypto; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 11/94 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 83/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies primexa.cc as an active cryptocurrency drainer scam domain designed to steal digital assets through deceptive financial service impersonation. The site mimics legitimate trading or exchange platforms to trick users into connecting cryptocurrency wallets, enabling unauthorized fund transfers via drainer scripts embedded in the interface. This threat type specifically targets Web3 users engaging with DeFi or exchange-like services. This domain was flagged by 6 out of 95 VirusTotal security vendors, indicating a strong but not universal detection consensus. It resolves to IP address 104.21.3.109 and was registered on January 15, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. The domain holds a valid SSL certificate issued by Google Trust Services, which is commonly exploited in phishing campaigns to appear trustworthy. Additionally, the recent creation date—occurring in early 2026—suggests a hastily deployed threat designed to capitalize on current market or platform trends without long-term infrastructure stability. PhishDestroy assesses the risk level as elevated due to active hosting, drainer functionality, and partial detection coverage. The domain remains online and operational as of this assessment, with no public takedown or blocklist action recorded. Users are strongly advised to block access to 104.21.3.109 and avoid any connection to primexa.cc. If any cryptocurrency-related interaction has occurred, disconnect wallets immediately, revoke any suspicious permissions, and transfer remaining assets to a secure wallet. Remaining risk is high for exposed users and may persist until the domain or associated infrastructure is neutralized.
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
Latest Classified Outcome 2026-08-08 04:13:22 UTC
التقنيات · 4 identified
Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comPerformance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comتحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of primexa.cc · checked Apr 20, 2026
الأدلة والتقارير الخارجية
PD-20260420-848093 Recipient: abuse@nicenic.net هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب