Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@tonic.to.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
monero2mix[.]to
“Monero Mixer | Enhance XMR Privacy with Anonymous Coin Mixing”
monero2mix.to — Неперевірений. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar, Webroot); PhishDestroy score 88/100. Реєстратор: Government of Kingdom ….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of monero2mix.to indicates it is an active fraudulent cryptocurrency mixing service targeting Monero (XMR) users. The domain was registered on July 3, 2025, through the Government of the Kingdom of Tonga, and remains operational as of July 12, 2026. The page title, 'Monero Mixer | Enhance XMR Privacy with Anonymous Coin Mixing,' explicitly advertises coin mixing services, a common lure for cryptocurrency theft or money laundering schemes. Infrastructure analysis reveals the domain resolves to IP address 188.114.96.3 and is protected by Cloudflare, utilizing HTTP/3 for communication. The domain holds a Gridinsoft trust score of 0/100 and is blocked by PhishDestroy and BLP-Malware. It appears on two security blocklists and has been included in 23 AlienVault OTX threat intelligence pulses, indicating widespread detection as malicious. Five security vendors on VirusTotal flag the domain, though this represents a minority of engines and should not be interpreted as definitive evidence of compromise. The SSL certificate is issued by Google Trust Services, which does not inherently validate the legitimacy of the site. Defenders should treat this domain as high-risk and block it at the network level. Users attempting to access cryptocurrency mixing services should verify the legitimacy of such platforms through trusted sources, as monero2mix.to exhibits multiple indicators of fraudulent activity. Further investigation is recommended to determine the extent of user interaction and potential financial losses associated with this domain.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of monero2mix.to · checked Jul 12, 2026
Докази та зовнішні звіти
PD-1776690264-monero2mix.to Recipient: abuse@tonic.to Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога