zeusmix[.]io
“Ethereum Mixer (Litecoin Mixer), Solana Mixer | ZeusMix”
Riepilogo delle prove
Analysis of zeusmix.io, observed on July 24, 2026, shows a domain created on March 05, 2026 that is currently offline but was previously associated with a crypto‑mixing service claiming to support Solana. The page title retrieved from the site, "Ethereum Mixer (Litecoin Mixer), Solana Mixer | ZeusMix," explicitly references Solana, confirming the brand impersonation described in the threat profile. The domain resolves to IP address 188.114.97.3, which belongs to Cloudflare, Inc. (AS13335) and is geolocated to the United States. DNS records list jose.ns.cloudflare.com and tegan.ns.cloudflare.com as authoritative nameservers, indicating the infrastructure is hosted behind Cloudflare’s edge network.
The SSL certificate is issued by Google Trust Services under the WE1 intermediate, showing a valid TLS configuration but offering no protection against malicious content. Vendor detection data from VirusTotal records eight of ninety‑four security scanners flagging the domain, reinforcing the suspicion of malicious activity. The domain appears on one external blocklist and has been explicitly blocked by PhishDestroy, further evidencing its classification as a crypto scam. Gridinsoft assigns a trust score of 1 out of 100, reflecting an extremely low confidence in the domain’s legitimacy.
The registrar listed is NiceNIC International Group Co., Limited, a known provider for many short‑lived malicious registrations. While the site is now taken offline, the combination of brand impersonation, low trust rating, vendor detections, and blocklist entries suggests that zeusmix.io was operated to deceive Solana users seeking mixing services. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any re‑registration attempts, and include the associated IP and certificate fingerprints in threat‑intel feeds. Ongoing vigilance is recommended as the underlying hosting provider can be leveraged for future malicious domains.
Data Coverage
Indicatori di sicurezza
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
VirusTotal
0 → 2
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo