welcome-cd-mexx-help[.]pages[.]dev
“MEXC Exchange - Cryptocurrency Exchange for Bitcoin, Ethereum …”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
PhishDestroy's threat intelligence identifies welcome-cd-mexx-help.pages.dev as a credential theft endpoint deployed under Cloudflare Pages. The domain is structured to impersonate a customer support or help portal, a common tactic used to harvest user credentials under the guise of service resolution. Based on seed d5b7b3, the lure targets users seeking 'help' or 'support', likely distributed via impersonation emails or spoofed support tickets targeting enterprise or SaaS users. No cryptocurrency drainer kit signatures (e.g., Etherscan, TronLink) were observed during sandbox analysis, indicating this campaign focuses on harvesting login credentials rather than direct asset exfiltration.
This domain was flagged by PhishDestroy with a current detection ratio of 1 out of 95 engines on VirusTotal, indicating it remains under the radar. The domain resolves to IP 172.66.44.87 via Cloudflare’s proxy network, a typical hosting configuration used to evade detection and facilitate rapid domain rotation. The domain was registered through Cloudflare, Inc., leveraging their free tier (Cloudflare Pages), and utilizes a Google Trust Services SSL certificate to enhance legitimacy. While the exact registration date is not publicly disclosed due to Cloudflare’s privacy protections, the domain has been observed resolving and serving content since deployment on the platform. Google Safe Browsing (GSB) has not yet flagged this domain, and while historical blocklist data is limited due to its recent activation, its structure and content align with known TTPs in credential harvesting campaigns.
At this time, the domain is classified as 'active' with a status of 'under_investigation' by PhishDestroy’s automated pipeline. No direct takedown has been initiated, and no third-party blocklists have flagged it, enabling sustained operation. The primary exposure vector is through spear-phishing emails or hijacked support threads, targeting users expecting assistance. The remaining risk is assessed as moderate due to the domain’s clean initial detection profile and reliance on user trust rather than technical exploit. Immediate action is recommended: users should avoid interacting with this domain and report any suspicious login prompts. Security teams should update threat intelligence feeds to include this IOC (172.66.44.87, welcome-cd-mexx-help.pages.dev) and monitor for lateral movement in associated accounts.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of welcome-cd-mexx-help.pages.dev · checked Apr 18, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога