coinmix[.]co[.]uk
“Coin Mix – Cryptocurrency Mixing Platform”
coinmix.co.uk — Неперевірений. Уособлення бренду: Across; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 2/91 (CRDF, Gridinsoft); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100. Реєстратор: NameSilo.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of coinmix.co.uk, observed on July 24, 2026, indicates that the domain was registered through NameSilo, LLC on 17 October 2025 and uses the hostsilo.com name servers (ns1.hostsilo.com, ns2.hostsilo.com). The site presented the page title “Coin Mix – Cryptocurrency Mixing Platform”, suggesting a cryptocurrency mixing service, but the underlying threat classification is brand impersonation. No TLS certificate was observed, leaving the connection unencrypted. DNS resolution points to IP address 64.187.97.203, which is registered to AS400343 belonging to NAMESILO, L.L.C. and geolocated to Canada. The IP and hosting information do not reveal any additional infrastructure beyond the registrar’s network.
The domain appears on four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—each of which has flagged the domain for malicious activity. VirusTotal scanning reported three positive detections out of ninety‑five security vendors, reinforcing the suspicion of malicious intent. Gridinsoft assigned a trust score of 0 out of 100, the lowest possible rating, indicating extreme lack of trustworthiness. The site’s current status is reported as offline, which may limit immediate observation but does not remove the historical risk.
Given the convergence of registrar‑based registration, absence of SSL, low trust score, multiple blocklist entries, and positive VirusTotal detections, the evidence supports a high confidence assessment that coinmix.co.uk was employed for brand impersonation targeting users interested in cryptocurrency services. Uncertainty remains regarding the exact phishing kit, payload delivery mechanisms, or any compromised credentials, as no detailed page content or traffic logs are available. Defenders should continue to block the domain at network perimeters, monitor for any residual DNS queries or connections to 64.187.97.203, and incorporate the indicator set (domain, IP, and associated blocklist tags) into threat‑intel feeds.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога