dexchang[.]net
Análisis de phishing y seguridad de dexchang.net
“Dex Exchange | Моментальный обмен криптовалют”
dexchang.net — Contenido no disponible (HTTP 502). Suplantación de marca: Avalanche; Tipo de estafa: Fake Exchange. Resumen de las pruebas: VirusTotal 1/93 (Webroot); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
On 24 July 2026 the domain dexchang.net was observed hosting a fraudulent cryptocurrency exchange front. The site’s HTML title reads “Dex Exchange | Моментальный обмен криптовалют”, indicating an attempt to present a rapid crypto‑swap service. The domain was registered on 21 February 2026 and resolves to the Cloudflare address 172.67.172.152, an IP block (AS13335) owned by Cloudflare, Inc. The SSL certificate is identified as “WE1”, which is typical for Cloudflare‑issued certificates but provides no assurance of legitimacy. VirusTotal records show that 1 out of 93 scanning engines flagged the domain, suggesting at least one vendor detected malicious behavior.
The domain appears on four independent blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura, each classifying it as a fake exchange. Current network probes indicate the host is offline, matching the “taken offline” status reported by the intelligence feed. Evidence confirms the domain’s primary threat vector is a fake exchange that may lure victims into depositing cryptocurrency under false pretenses. No additional indicators such as malicious payload hashes, command‑and‑control endpoints, or phishing page screenshots have been released, leaving the full scope of the campaign uncertain.
Defenders should block DNS resolution for dexchang.net, add the associated IP 172.67.172.152 to deny‑list rules where feasible, and monitor traffic for attempts to contact the domain or its IP. Because the site leverages Cloudflare’s infrastructure, typical network‑level blocking may be limited; employing URL filtering or reputation‑based web proxy rules is recommended. Security teams should also update endpoint detection signatures with the single VirusTotal detection and ensure that any alerts from the listed blocklists trigger incident response workflows. Continuous re‑assessment is advised in case the domain is re‑hosted or the threat actors shift to new infrastructure.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.