coinexglobals[.]org
“Coinextrading - Your Peddle to Better Profit”
coinexglobals.org — Контент недоступний (HTTP 502). Уособлення бренду: Across; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 67/100. Реєстратор: GMO Internet Group.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of coinexglobals.org indicates a high‑risk brand impersonation operation targeting the "across" brand. The domain was registered on June 20, 2025 through GMO Internet Group, Inc. d/b/a Onamae.com and currently resolves to IP address 198.23.193.170, which belongs to AS36352 (HostPapa) in the United States. The authoritative name servers are ns1.geebytescloud.com and ns2.geebytescloud.com, and the MX record points to the domain itself with priority zero, a configuration often used to facilitate spam or phishing email delivery. The site presents a page titled "Coinextrading - Your Peddle to Better Profit" and serves content over HTTP/3 using a LiteSpeed web server. Detected client‑side components include YouTube embeds, jQuery, jQuery UI, JivoChat, GetButton, and Clipboard.js, suggesting attempts to increase credibility and enable user interaction. The SSL certificate is issued by Let’s Encrypt (R13), providing encryption but not authentication of the underlying entity.
Reputation services flag the domain as extremely untrustworthy: Scamadviser assigns a trust score of 1/100, Gridinsoft scores 0/100, and the domain appears on one security blocklist. VirusTotal analysis shows that three of ninety‑five scanned vendors flagged the site, reinforcing the malicious assessment. PhishDestroy has already blocked the domain, and the HTTP response code is 200, indicating the site is actively serving content.
Defenders should add coinexglobals.org to URL filtering and email security policies, block its IP address, and monitor for related DNS queries to the listed name servers. Because the domain impersonates the "across" brand, organizations using that brand should issue user warnings and educate employees about the fraudulent page title and the lack of legitimate affiliation. Continuous observation of any new infrastructure changes, such as additional IPs or altered certificate authorities, is recommended to detect potential evolution of the campaign.
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 8 identified
YouTube is a video sharing service where users can create their own profile, upload videos, watch, like and comment on other videos.
www.youtube.com 100% впевненостіjQuery UI is a collection of GUI widgets, animated visual effects, and themes implemented with jQuery, Cascading Style Sheets, and HTML.
jqueryui.com 100% впевненостіjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% впевненостіJivoChat is a live chat solution for websites offering customizable web and mobile chat widgets.
www.jivosite.com 100% впевненостіThe chat button by GetButton takes website visitor directly to the messaging app such as Facebook Messenger or WhatsApp and allows them to initiate a conversation with you.
getbutton.io 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога