eth.criptopayment[.]com
Forensic brief
Read full brief
PhishDestroy identifies eth.criptopayment.com as a fraudulent domain actively posing as a cryptocurrency payment portal to harvest sensitive wallet credentials and private keys. The site employs deceptive branding to trick users into entering login details or transferring crypto assets, with malicious infrastructure hosted on IP 172.67.149.9. Security researchers have observed this domain engaging in credential phishing campaigns targeting Ethereum and other digital asset users, creating a high-risk environment for unknowing visitors.
This domain was flagged by PhishDestroy after analysis revealed critical threat indicators, including 7/95 VirusTotal detection rates as of the most recent scan, indicating that mainstream antivirus engines have not yet flagged the infrastructure. The domain was registered on May 09, 2026, through Internet Domain Service BS Corp., using a Let's Encrypt SSL certificate to appear legitimate. Despite its recency, the domain is already associated with multiple reports within security research communities, raising concerns about its rapid deployment in active phishing operations.
Users who visited eth.criptopayment.com should immediately cease any interaction with the site and avoid entering any cryptocurrency wallet addresses, private keys, or login credentials. It is recommended to scan all connected devices for malware using updated antivirus software and to revoke any session tokens or API keys that may have been exposed. If any transactions were made or credentials were entered, contact your wallet provider immediately and consider transferring remaining funds to a newly generated, secure wallet address.
Report the domain to your cybersecurity team or relevant authorities to help prevent further exploitation.
Threat response pipeline
Cloudflare Radar
VirusTotal
Forensic Evidence Collectionabuse@internet.bs with forensic evidence (metadata, screenshots, PDF).Evidence capture
Domain Intelligence
Internet Domain Service BS Corp.
Technical details
Public blocklist status
Technologies
Technologies · 3 identified
VirusTotal consensus
Aggregated detection across 95 security vendors.
Site performance
Site performance analysis
Google PageSpeed Insights — mobile audit of eth.criptopayment.com
Evidence & external reports
Were you affected by this site?
Were You Affected?
Recommendations & Advice for Victims
- Do not pay anything else. Recovery agents demanding upfront fees are a second-stage scam.
- Disconnect compromised wallets. Move remaining funds to a fresh seed phrase generated offline.
- Preserve evidence. Screenshot transactions, save URLs, archive emails — chain-of-custody matters for prosecution.
- Report to authorities (see section 15 below) — even small reports help build case patterns.
- Notify your bank/exchange. Some chargebacks may still be possible within 24-72h.
Report to your local authorities
Email template — registrar abuse
abuse@internet.bs
Registrar: Internet Domain Service BS Corp. Case: PD-20260512-B04335
Embed this report
About this report
About this report: eth.criptopayment.com
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal and 1 public blocklists.
The site displays a page titled “Document”.
eth.criptopayment.com has been flagged by 7 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.