in-cryptomus[.]com
in-cryptomus.com 피싱 및 보안 점검
“Cryptomus Pay”
in-cryptomus.com — 콘텐츠를 사용할 수 없음 (HTTP 404). 증거 요약: VT 3/95 (Gridinsoft, SOCRadar, URLQuery); URLQuery 4 alerts; URLScan no malicious verdict; GSB no flag; Spamhaus DBL_PHISH; BL 2 (MetaMask, SEAL); PD 78/100. 등록기관: NameCheap.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies in-cryptomus.com as a generic phishing domain impersonating the legitimate Cryptomus Pay platform. This fraudulent site was designed to steal login credentials or sensitive financial information from unsuspecting users. The domain mimics the official Cryptomus brand to appear trustworthy, but its sole purpose is to facilitate credential harvesting or other malicious activities.
Technical analysis reveals several red flags. The domain was registered through NameCheap, Inc. and created on February 21, 2026, which is notably in the future, indicating likely data manipulation or a test environment. It resolves to IP address 216.198.79.1 and uses a Let's Encrypt/R12 SSL certificate, which provides encryption but does not guarantee legitimacy. VirusTotal shows 3 out of 95 security vendors flagging the domain, and it appears on 3 security blocklists. These indicators confirm that the domain is widely recognized as malicious.
Currently, the domain has been taken offline, mitigating immediate risk to users. However, the threat remains that similar domains may appear under different names or IPs. Users who may have interacted with this site should change any passwords entered and monitor accounts for unauthorized activity. PhishDestroy recommends always verifying URLs before entering sensitive information, especially for financial platforms like Cryptomus. Stay vigilant against future phishing attempts by checking domain creation dates and security reports.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | www.in-cryptomus.com/assets/secure.php?req=ping |
malware | PHP webshell obfuscated by encoding of mixed hex and dec |
| Nextron YARA rules | www.in-cryptomus.com/assets/secure.php?req=ping |
malware | Known PHP Webshells which contain unique strings, lousy rule for low hanging fruits. Most are catched by other rules in here but maybe these catch different ver |
| Quad9 DNS | public-bsc.nownodes.io |
malicious | Sinkholed |
| DNS4EU | fbsfoewlknwkpew111.live |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
ICANN은 돈을 받았다. 책임은 끝내 오지 않았다.
이 gTLD에서 위 등록기관은 ICANN과의 계약에 따라 운영됩니다. ICANN은 등록, 갱신 및 이전과 연계된 연간 수수료, 변동 수수료 및 거래 기반 수수료를 징수합니다.
인증: 수익화 완료. 책임: 나중에 다시 확인하십시오.
그러고 나면 마법이 시작됩니다. ICANN은 RAA §3.18을 작성하고, 등록기관은 자기 고객 기반 안의 악용을 스스로 조사하며, 피해자는 증거를 공짜로 제공하는 동안 모든 단계는 다른 누군가가 움직이기만을 기다립니다. 그 덕분에 피해자가 더 안전하다고 느낀다면 훌륭합니다—청구서가 제 몫을 한 셈이니까요.
사용 기술 · 2 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 신뢰도 100%VirusTotal 분석
보관된 증거
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of in-cryptomus.com · checked Mar 2, 2026
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.