ethereum-mixer[.]org
“ETH Mixer - Best Ethereum Mixer for Anonymous Crypto Transactions”
ethereum-mixer.org — No verificado. Suplantación de marca: Ethereum; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 16/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 1 alert; URLScan malicious verdict; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 100/100. Registrador: Epik.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
ethereum-mixer.org is an active brand‑impersonation site that masquerades as an Ethereum mixing service. The page title “ETH Mixer – Best Ethereum Mixer for Anonymous Crypto Transactions” directly references the Ethereum brand, indicating a targeted attempt to lure users seeking privacy‑focused cryptocurrency tools. The domain was registered on 07 Oct 2025 through Epik LLC and uses the authoritative name servers ns3.epik.com and ns4.epik.com. No evidence suggests the domain is part of a broader campaign beyond the observed activity. Network analysis shows the domain resolves to IP 198.187.31.223, an address hosted in the United States and assigned to AS22612, which is owned by Namecheap, Inc. The web server returns an HTTP 301 redirect and presents a Sectigo Public Server Authentication CA DV R36 certificate, a standard domain‑validated certificate that does not provide any additional trust. The low Gridinsoft trust score of 0 / 100 further confirms the malicious nature of the host. Reputation data corroborates the malicious classification. The site is listed on five independent security blocklists, including PhishDestroy, Polkadot, Enkrypt, Codeesura, and PhishingDB. AlienVault OTX has referenced the domain in fourteen threat‑intelligence pulses, and VirusTotal reports sixteen of ninety‑five scanning engines flagging the domain as malicious. The cumulative evidence places the risk level at high, and the current status remains active. Defenders should immediately block resolution of ethereum-mixer.org at the network perimeter and update endpoint detection rules to flag any HTTP 301 responses containing the “ETH Mixer” title. Continuous monitoring of the associated IP 198.187.31.223 and its ASN is advised, as the infrastructure may be reused for additional cryptocurrency‑related scams. Incident response teams should also query the domain’s registrar (Epik LLC) for any related abuse contacts to facilitate takedown requests.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS0 Zero | ethereum-mixer.org |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Datos y informes externos
“Blacklist from EtherAddressLookup Database”
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.