btc-tumbler[.]to
“Secure Multi-Currency Crypto Mixer | Enhance Blockchain Privacy”
btc-tumbler.to — Контент недоступний. Уособлення бренду: Ethereum; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 16/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); CF Radar malicious; PhishDestroy score 100/100. Реєстратор: Government of Kingdom ….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain btc-tumbler.to was registered on May 24, 2024 through a registrar identified as the Government of the Kingdom of Tonga. It resolves to the IP address 45.12.2.86, which is allocated to AS6698 Virtual Systems LLC in Ukraine and is served by an Nginx web server that enforces HTTP Strict Transport Security. The site presented a page title of "Secure Multi-Currency Crypto Mixer | Enhance Blockchain Privacy," indicating a crypto‑mixing service that falsely claims affiliation with the Ethereum brand. The SSL certificate is issued by Let’s Encrypt (R13), and the domain is protected by HSTS, suggesting an attempt to appear legitimate.
Infrastructure analysis shows the domain is hosted on nameservers ns1.zomro.net and ns2.zomro.ru, both associated with the Zomro hosting provider. Reputation checks are uniformly negative: Gridinsoft assigned a score of 0 / 100, Scamadviser a score of 1 / 100, and the domain is listed on a security blocklist and flagged by PhishDestroy. AlienVault OTX reports the domain in a single threat‑intel pulse, and VirusTotal logged 16 detections out of 95 security vendors, reinforcing the malicious classification.
The site is currently offline, but the observed infrastructure—Ukrainian hosting, generic SSL, and brand‑impersonating page title—matches known patterns used in crypto‑mixing scams targeting Ethereum users. Defenders should continue to block the domain and its associated IP address, monitor any future re‑registration attempts, and educate users that legitimate Ethereum services never use such mixer terminology or unrelated hosting providers. Further analysis is required to confirm any additional payloads or redirects that may have been served before the takedown.
Сигнали безпеки
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of btc-tumbler.to · checked Mar 2, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога