presapexmarkets[.]com
“Problem loading page”
presapexmarkets.com — Контент недоступний (HTTP 502). Уособлення бренду: Genericscam; Тип шахрайства: Fake Exchange. Зведення доказів: VirusTotal 10/91 (alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker, Fortinet); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 100/100. Реєстратор: Global Domain Group.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, presapexmarkets.com, is flagged as an elevated-risk phishing infrastructure specifically designed for credential harvesting targeting financial and cryptocurrency trading platforms. Analysis indicates the site impersonates legitimate trading services to deceive users into submitting login credentials, API keys, or wallet recovery phrases, which are then exfiltrated to attacker-controlled endpoints. The threat type aligns with patterns observed in fake trading platform scams, where brand impersonation and social engineering are leveraged to exploit victims under the guise of market access or investment opportunities. Infrastructure analysis reveals the following technical indicators: the domain was registered on June 08, 2026, through Global Domain Group LLC, a registrar frequently associated with high-risk domains. It resolves to the IP address 163.61.188.9 and has been flagged by 10 out of 95 security vendors on VirusTotal, with detections spanning generic phishing, brand impersonation, and malicious URL categories. The domain appears on at least one security blocklist and has been documented in four threat intelligence pulses on AlienVault OTX. Gridinsoft assigns a trust score of 1/100, further corroborating its malicious classification. Frontend technologies detected include PHP, YouTube embeds, Tailwind CSS, LiteSpeed, Alpine.js, Unpkg, Smartsupp, and jQuery CDN, suggesting a sophisticated but templated approach to mimic legitimate trading platforms. The page title 'Problem loading page' may indicate a failed deployment, takedown, or deliberate evasion tactic to avoid detection during active campaigns. Mitigation steps for this specific threat type include immediate blacklisting of the domain and its associated IP (163.61.188.9) across network security controls, including firewalls, DNS filters, and email gateways. Organizations should deploy indicators of compromise (IOCs) such as the domain, IP, and registrar details (Global Domain Group LLC) into security information and event management (SIEM) systems to detect potential lateral movement or data exfiltration attempts. End users should be educated on recognizing fake trading platforms, particularly those using urgent calls-to-action (e.g., limited-time offers, account verification demands) or spoofed branding. Multi-factor authentication (MFA) should be enforced for all financial and cryptocurrency accounts to mitigate credential theft risks. Incident responders should monitor for unauthorized access attempts originating from the identified infrastructure, particularly in environments where trading or investment-related services are accessed.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 11 identified
YouTube is a video sharing service where users can create their own profile, upload videos, watch, like and comment on other videos.
www.youtube.com 100% впевненостіSmartsupp is a live chat tool that offers visitor recording feature.
www.smartsupp.com 100% впевненостіjQuery CDN is a way to include jQuery in your website without actually downloading and keeping it your website's folder.
code.jquery.com 100% впевненостіjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% впевненостіThe chat button by GetButton takes website visitor directly to the messaging app such as Facebook Messenger or WhatsApp and allows them to initiate a conversation with you.
getbutton.io 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of presapexmarkets.com · checked Jun 26, 2026
Докази та зовнішні звіти
PD-20260608-1E0327 Recipient: abuse@whiteprivacy.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога