# bitplax.com — SUSPICIOUS > bitplax.com poses a medium-risk brand impersonation threat targeting Ethereum users. Stay vigilant and avoid this domain now. ## Summary PhishDestroy identifies bitplax.com as a medium-risk brand impersonation domain pretending to represent Ethereum. Classified under brand impersonation, this domain attempts to deceive users by mimicking a reputable cryptocurrency brand to gain trust. The domain bitplax.com was registered on March 12, 2026, through NiceNIC International Group Co., Limited. It appeared on three security blocklists and was flagged by four security vendors on VirusTotal out of 95 scans. The domain resolved to IP address 172.67.220.171 and hosted a page titled "Buy & Sell Bitcoin, Ethereum | Cryptocurrency Exchange | Bitmadex," designed to lure victims into fraudulent cryptocurrency transactions. Currently, bitplax.com is offline, reflecting a successful takedown effort. Users and organizations are advised to remain cautious of potential phishing attempts linked to this domain or similar variants. PhishDestroy continues to monitor any resurgence or related threats using the unique seed 015006 for ongoing threat analysis. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 0) - Target brand: Ethereum - Page title: Buy & Sell Bitcoin, Ethereum | Cryptocurrency Exchange | Bitmadex ## Domain Intelligence - Registered: 2026-03-12 03:07:01 - Registrar: NiceNIC International Group Co., Limited - Country: HK - IP: 172.67.220.171 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ["nolan.ns.cloudflare.com", "zelda.ns.cloudflare.com"] - SSL Issuer: Google Trust Services / WE1 ## Detection Status - VirusTotal: 4 vendors flagged Vendors: ["alphaMountain.ai", "CRDF", "Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019ce201-a6b9-7071-89f9-2ab6876cebb6.png - PhishDestroy: https://phishdestroy.io/domain/bitplax.com/ - LLM endpoint: https://phishdestroy.io/domain/bitplax.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/bitplax.com/ Last updated: 2026-03-19