keiwex[.]com
Análisis de phishing y seguridad de keiwex.com
“Keiwex: Elon Musk’s Official Crypto Casino Powered by Blockchain”
keiwex.com — Contenido no disponible (HTTP 502). Suplantación de marca: Genericcrypto; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 12/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis indicates that the domain keiwex.com was registered on February 21 2026 through NiceNIC International Group Co., Limited and immediately pointed to Cloudflare infrastructure (nameservers dilbert.ns.cloudflare.com and maya.ns.cloudflare.com). DNS resolution maps the hostname to IP 172.67.184.126, which belongs to AS13335 owned by Cloudflare, Inc., placing the server in the United States. The site presented the page title “Keiwex: Elon Musk’s Official Crypto Casino Powered by Blockchain,” suggesting an attempt to lure victims with a fabricated endorsement from Elon Musk and a cryptocurrency casino narrative. Detection services have flagged the domain: twelve of ninety‑five VirusTotal scanners raised alerts, and the site is listed on a single public blocklist.
It has been blocked by the PhishDestroy service. Technical fingerprints show the presence of Twitter Ads, Facebook Pixel, Cloudflare Browser Insights, and generic Cloudflare services, all typical of a credential‑harvesting landing page. The observed phishing kit is identified as the “Gambler Scam,” and the overall scam type is classified as a crypto scam. No SSL certificate was observed, indicating that the site operated without HTTPS.
Current HTTP status is offline, confirming that the malicious page has been taken down. Uncertainties remain regarding the volume of victim interaction, the specific payload delivered, and whether any cryptocurrency wallets were compromised. Defenders should continue to block keiwex.com at DNS and proxy layers, monitor for any re‑hosting attempts on other Cloudflare IP ranges, and update threat‑intel feeds with the observed indicators of compromise, including the domain name, IP address, registrar, and detected tracking scripts. Additional surveillance of related Gambler Scam campaigns is recommended to capture any resurgence of the same infrastructure.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-08 04:01:35 UTC
Tecnologías · 4 identified
Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comPerformance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externos
PD-20260219-17AD78 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.