exchange[.]mercuryo[.]io
“Mercuryo | Cryptocurrency Exchange Service Available 24/7”
exchange.mercuryo.io — Неперевірений. Уособлення бренду: GMX; Тип шахрайства: Fake Exchange. Зведення доказів: VirusTotal 2/91 (Chong Lua Dao, Gridinsoft); PhishDestroy score 61/100. Реєстратор: GoDaddy.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of exchange.mercuryo.io indicates active brand impersonation targeting GMX, classified as a high-risk fake cryptocurrency exchange. The domain was registered on February 21, 2026, through GoDaddy.com, LLC, with an SSL certificate issued by GoDaddy.com, Inc. (Go Daddy Secure Certificate Authority - G2). It resolves to IPv6 address 2a05:d014:1b25:8366:9c62:441f:a8:e3a9, hosted on Amazon.com, Inc. infrastructure (AS16509, DE). Nameservers are AWS-based (ns-1161.awsdns-17.org, ns-1964.awsdns-53.co.uk, ns-483.awsdns-60.com, ns-873.awsdns), and the HTTP response status is 200, confirming the site is operational.
Detection data is limited: one of 93 security vendors on VirusTotal flags the domain, and it appears on a single blocklist (PhishDestroy). The page title, 'Mercuryo | Cryptocurrency Exchange Service Available 24/7,' aligns with the reported scam type (fake exchange). Trust scores are low: Gridinsoft rates it 1/100, while Scamadviser assigns 31/100. Technologies detected include Zendesk, HSTS, Google Analytics, and Forethought Solve, which may be used to lend legitimacy or track victims.
No evidence confirms whether this domain employs credential harvesting, wallet-draining scripts, or other attack vectors. Defenders should treat it as an active phishing resource impersonating GMX, block the domain and associated IP, and monitor for related infrastructure (e.g., AWS-hosted domains with similar naming patterns or SSL issuers). Further analysis of the site’s content and backend is required to determine exact payloads or redirection chains.
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
Customer support ticketing platform.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comАналіз VirusTotal
Архівні докази
Аналіз конфігурації сайту
Докази та зовнішні звіти
“Classic payPal and advance payment scam. Screen is in czech but you can translate it. Overall it seems already just from the pictures and email structure”
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога