cryptomus[.]ltd
Verificação de phishing e segurança de cryptomus.ltd
“Cryptomus Exchange | Crypto Invoice”
cryptomus.ltd — Conteúdo indisponível (HTTP 502). Representação da marca: Bitget; Tipo de golpe: Wallet/seed Phishing. Resumo das evidências: VirusTotal 14/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 92/100. Registrador: PDR.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain cryptomus.ltd has been identified as a phishing infrastructure designed for brand impersonation, specifically targeting users of the cryptocurrency exchange Bitget. Analysis confirms the domain is currently offline, though prior activity involved presenting a fraudulent interface under the page title 'Cryptomus Exchange | Crypto Invoice,' mimicking legitimate cryptocurrency payment and exchange services. The threat type is classified as brand impersonation, a tactic commonly employed to deceive users into disclosing credentials or transferring funds under false pretenses.
Technical indicators reveal multiple red flags. The domain was registered through PDR Ltd. d/b/a PublicDomainRegistry.com on February 21, 2026, an unusually future-dated registration likely intended to evade immediate scrutiny. It resolves to the IP address 104.21.82.10, a Cloudflare-associated address often used to obscure hosting origins. Detection metrics show 14 of 95 security vendors on VirusTotal flagged the domain as malicious, while Scamadviser assigned a trust score of 31 out of 100, and Gridinsoft rated it 0 out of 100. The domain appears on one security blocklist and is referenced in a single threat intelligence pulse on AlienVault OTX. These indicators collectively suggest a low-reputation, high-risk infrastructure.
Current status indicates the domain has been taken offline, likely in response to detection and mitigation efforts. However, the infrastructure may resurface under altered domains or IP configurations. Organizations and users are advised to implement proactive measures, including blocking the domain and associated IP at network perimeters, updating endpoint detection rules to include known indicators of compromise, and conducting user awareness training to recognize brand impersonation tactics. Monitoring for newly registered domains with similar naming conventions or hosting patterns is recommended to preempt potential resurgence of this campaign.
Sinais de segurança
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Histórico de denúncias de abuso · 3 stored reports over 2 days · click to expand
-
Report #1 Jan 29, 2026 · 16:43 UTCPhishing Abuse Report: cryptomus[.]ltdabuse@publicdomainregistry.com
-
Report #2 Escalation 14h still active Jan 30, 2026 · 06:49 UTCESCALATION #2 (14h active): Phishing - cryptomus[.]ltdabuse@publicdomainregistry.com
-
Report #3 Escalation 25h still active Jan 30, 2026 · 18:05 UTCESCALATION #3 (25h active): Phishing - cryptomus[.]ltdabuse@publicdomainregistry.com
Análise do VirusTotal
Evidências e relatórios externos
PD-1769704993-cryptomus.ltd Recipient: abuse@publicdomainregistry.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo