ethereum[.]com[.]mx
“Contact Support”
Observation enregistrée
Contraste de titres observé
Résumé des preuves
This domain, ethereum.com.mx, was registered on March 21, 2016 through the registrar Wingu Networks S.A de C.V. and is hosted on a server owned by Network Solutions, LLC (ASN 19871) in the United States, resolving to the IPv4 address 192.185.16.54. The authoritative name servers are ns8013.hostgator.com and ns8014.hostgator.com, and the site presents a TLS certificate issued by Let’s Encrypt (R13), indicating that HTTPS is available despite the server returning an HTTP 401 (Unauthorized) response for the default request. The page title returned by the web server is “Contact Support”, which does not reveal any brand‑specific content but aligns with the reported impersonation of the Ethereum brand and a declared crypto‑scam motive. Multiple detection engines have flagged the domain.
VirusTotal reports that 17 of 93 security vendors label the host as malicious, and AlienVault OTX includes the domain in three separate threat‑intel pulses. The site is currently listed on one public blocklist and has been blocked by the PhishDestroy service. Independent reputation scoring from Gridinsoft assigns a trust score of 0 out of 100, reinforcing the high‑risk assessment. The evidence points to a classic brand‑impersonation campaign targeting users of the Ethereum ecosystem, likely attempting to harvest credentials or funds under the guise of a support contact.
However, the exact content served beyond the title is not publicly available, and the specific phishing or malware payload, if any, remains unknown. Defenders should continue to block the domain at network perimeter devices, update DNS filtering with the known IP address 192.185.16.54 and associated hostnames, and monitor for any outbound connections to the server. Incident response teams should also treat any communications referencing “Contact Support” from the Ethereum brand as suspicious and advise users to verify official support channels through known Ethereum resources.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif