# coxwex.com — SUSPICIOUS > coxwex.com hosts a brand impersonation crypto drainer with 0/95 VirusTotal detections. Created Dec 12, 2025 via MAT BAO CORPORATION. ## Summary PhishDestroy identifies coxwex.com as an active domain engaged in crypto drainer operations designed to mimic legitimate services and steal cryptocurrency assets. This malicious site employs techniques such as counterfeit brand interfaces and deceptive deposit addresses to trick users into authorizing unauthorized transactions. The domain resolves to 172.67.171.202 and leverages a Google Trust Services SSL certificate to appear legitimate, creating a false sense of security for potential victims. This domain was flagged with 0 detections out of 95 VirusTotal scans, indicating it has evaded detection by most antivirus engines as of current analysis. The domain was registered on December 12, 2025 through MAT BAO CORPORATION, a registrar that has been previously observed facilitating malicious domain registrations. These operational tactics suggest an active and evolving threat designed to bypass standard security measures while targeting cryptocurrency users. If you accessed coxwex.com, immediately disconnect from the internet and run a full antivirus scan. Check your cryptocurrency wallet transaction history for any unauthorized transfers and revoke any suspicious approvals. Report the domain to your security team and submit it to threat intelligence platforms using the domain coxwex.com and IP address 172.67.171.202. Implement network blocks for this domain and IP to prevent further exposure within your environment. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-12-12 18:48:42 - Registrar: MAT BAO CORPORATION - IP: 172.67.171.202 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/coxwex.com - PhishDestroy: https://phishdestroy.io/domain/coxwex.com/ - LLM endpoint: https://phishdestroy.io/domain/coxwex.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/coxwex.com/ Last updated: 2026-04-04