# pcrtal.tmgmexchanges.vip — SUSPICIOUS > pcrtal.tmgmexchanges.vip mimics MEXC brand and is under investigation. Stay cautious and avoid sharing personal info on this site. ## Summary PhishDestroy identifies pcrtal.tmgmexchanges.vip as a potentially malicious domain impersonating the well-known cryptocurrency exchange brand MEXC. The domain was registered on August 17, 2025, raising suspicion due to its recent creation date and connection to a brand imitation attempt. Currently, its risk level remains under investigation, as no direct malware or phishing detections have been flagged by major security vendors. From a technical perspective, the domain is registered through Gname.com Pte. Ltd. and resolves to IP address 116.204.186.140. It exhibits a relatively poor PageSpeed score of 39/100, which is indicative of quickly assembled webpages often found in phishing campaigns. Despite none of the 95 antivirus engines on VirusTotal flagging the domain at this time, the low performance and brand impersonation nature warrant caution. At present, pcrtal.tmgmexchanges.vip remains active and under scrutiny by PhishDestroy. Users are advised to remain vigilant and avoid interacting with the site or submitting any personal credentials. Continuous monitoring is recommended to detect any emergent threats associated with this domain, and organizations may consider blocking it proactively to mitigate potential phishing risks. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP ?) - Target brand: MEXC ## Domain Intelligence - Registered: 2025-08-17 13:44:59 - Registrar: Gname.com Pte. Ltd. - Country: SG - IP: 116.204.186.140 - Nameservers: a9.share-dns.com b9.share-dns.net ## Detection Status - VirusTotal: 0 vendors flagged Vendors: [] - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Screenshot: https://urlscan.io/screenshots/019cf701-7017-7702-b20f-7d60723dd2b1.png - Cloudflare Radar: https://radar.cloudflare.com/scan/debf6705-ca5a-48fe-bfd9-9d8a4e3b77b2 - PhishDestroy: https://phishdestroy.io/domain/pcrtal.tmgmexchanges.vip/ - LLM endpoint: https://phishdestroy.io/domain/pcrtal.tmgmexchanges.vip/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/pcrtal.tmgmexchanges.vip/ Last updated: 2026-03-19