cex-io-user-login[.]at
“CEX io Prijava Berza | cex io login”
cex-io-user-login.at — Контент недоступен. Олицетворение бренда: CEX IO; Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 17 detections (engine total unavailable) (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); URLQuery 3 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. Регистратор: Iqweb.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, cex-io-user-login.at, is a credential phishing infrastructure designed to harvest login credentials from users attempting to access the legitimate CEX.IO cryptocurrency exchange platform. The domain mimics the official CEX.IO login interface, presenting a page titled 'CEX io Prijava Berza | cex io login,' which targets users through localized language deception. Analysis indicates the domain is engineered to capture usernames, passwords, and potentially two-factor authentication codes, enabling unauthorized access to victim accounts and subsequent theft of digital assets. Infrastructure analysis reveals multiple technical indicators confirming malicious intent. The domain was registered on February 27, 2026, through the registrar Iqweb, and resolves to the IP address 186.2.175.29, hosted on AS59692 (IQWeb FZ-LLC) in Belize. Security vendor detection on VirusTotal shows 17 out of 95 engines flagging the domain as malicious, while it appears on one security blocklist. The domain uses a Let's Encrypt SSL certificate (R12), which, while providing HTTPS encryption, does not validate legitimacy. The hosting provider and registration details align with patterns observed in credential phishing campaigns targeting financial platforms. Users who visited cex-io-user-login.at should immediately revoke any active sessions on the legitimate CEX.IO platform and change their login credentials. Enable multi-factor authentication using an authenticator application rather than SMS-based verification. Monitor account activity for unauthorized transactions and report any suspicious behavior to the platform's security team. If credentials were entered on this domain, assume they are compromised and avoid reusing them across other services. Security teams should block the domain and associated IP address (186.2.175.29) at the network perimeter to prevent further access attempts.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | cex-io-user-login.at |
phishing | Phishing Block |
| Cloudflare DNS | cex-io-user-login.at |
malicious | Sinkholed |
| DNS4EU | cex-io-user-login.at |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of cex-io-user-login.at · checked Mar 2, 2026
Доказательства и внешние отчеты
PD-20260227-099E6B Recipient: abuse@iqweb.io Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание