MALICIOUS — CRITICAL
benomex[.]com
On July 23, 2026, the domain benomex.com was observed to host a malicious site that impersonates the cryptocurrency exchange MEXC.
- VirusTotal
- 13/95
- Blocklists
- No stored match
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
benomex.com — Контент недоступен (HTTP 502). Олицетворение бренда: MEXC; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 100/100. Регистратор: Hello Internet.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
On July 23, 2026, the domain benomex.com was observed to host a malicious site that impersonates the cryptocurrency exchange MEXC. The page title returned by the server is "Benomex: Elon Musk’s Official Crypto Casino Powered by Blockchain", suggesting a crypto‑casino narrative. The domain was registered on February 21, 2026 through Hello Internet Corp and resolves to the Cloudflare‑managed address 172.67.134.27, hosted in the United States under ASN 13335. Nameservers dakota.ns.cloudflare.com and nataly.ns.cloudflare.com confirm the use of Cloudflare’s DNS infrastructure. No SSL certificate is presented, indicating an unencrypted HTTP service.
The site incorporates Twitter Ads, Facebook Pixel, and Cloudflare Browser Insights, reflecting typical tracking components used by malicious operators. Security telemetry shows the domain was blocked by PhishDestroy and appears on one external blocklist. VirusTotal analysis recorded 13 of 95 scanned security vendors flagging the domain as malicious. Independent trust scoring services assign low reputations: Gridinsoft 19/100 and Scamadviser 26/100, reinforcing the elevated risk assessment. The underlying malicious kit is identified as a "Gambler Scam", a known crypto‑scam framework that typically lures victims with promises of gambling profits.
The current operational status is offline, suggesting the infrastructure has been taken down or is temporarily unavailable. Uncertainties remain regarding the full content of the compromised page, as no visual inspection has been performed, and the exact mechanisms used to harvest credentials or funds are not disclosed. Defenders should continue to monitor DNS resolutions for benomex.com and related Cloudflare IP ranges, enforce blocklisting of the domain at network perimeters, and consider adding the associated IP address to threat intelligence feeds.
Охват данных14 recorded checks
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 4 identified
Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comPerformance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчетыIndependent lookups and source reports
PD-20260219-F91284 Recipient: abuse@hello.co Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.