zetomex[.]com
“zetomex.com | 521: Web server is down”
اكتشاف محفوظ
تنبيه إخفاء المحتوى
- نوع الإخفاء
status_split- درجة الإخفاء
- 4/6
ملخص الأدلة
This domain, zetomex.com, has been identified as a high‑risk brand‑impersonation site targeting the cryptocurrency exchange MEXC. The page title returned by the server is "zetomex.com | 521: Web server is down", indicating that the site is currently serving a generic error page rather than a crafted login portal. The domain is flagged by PhishDestroy and appears on a single external blocklist, confirming that security tooling already recognizes it as malicious.
The domain resolves to 104.21.6.149, an IP address owned by Cloudflare (AS13335) located in the United States. DNS resolution uses the Cloudflare nameservers roxy.ns.cloudflare.com and toby.ns.cloudflare.com. The site is delivered over HTTPS with a certificate issued by Google Trust Services (WE1) and negotiates HTTP/3, confirming that Cloudflare’s edge network is being leveraged. Registration occurred on 21 February 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com.
VirusTotal analysis reports that 4 of 95 security vendors have flagged the domain, suggesting partial detection across the ecosystem. AlienVault OTX includes the domain in one threat‑intelligence pulse, and Gridinsoft assigns a trust score of 0 out of 100, indicating an extremely low reputation. The HTTP response code is 200, meaning the server returns a successful status despite presenting an error page, a behavior often used to evade simple health‑check filters.
Defenders should block network connections to 104.21.6.149 and enforce DNS filtering for zetomex.com. Email gateways and web proxies must be updated to reject any URLs containing the domain. Continuous monitoring of Cloudflare‑served sub‑domains is advised, as the infrastructure could be repurposed for live phishing pages targeting MEXC users. Incident response teams should treat any credential or cryptocurrency transaction attempts involving this domain as compromised.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات
حُدّدَت تقنيتان عاليتا الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب