MALICIOUS — CRITICAL
kanimex[.]com
PhishDestroy identifies kanimex.com as an active brand impersonation domain targeting MEXC, designed to deceive users into connecting crypto wallets to a crypto-drainer kit.
- VirusTotal
- 15/94
- Blocklists
- No stored match
- sẵn có
- Che giấu · có thể truy cập · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 7 outgoing records; the latest is dated . The recorded recipient is abuse@trustname.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
kanimex.com — Che giấu · có thể truy cập (HTTP 403). Mạo danh thương hiệu: MEXC; Loại lừa đảo: Brand Impersonation. Tóm tắt bằng chứng: VirusTotal 15/94 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 2 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 100/100. Nhà đăng ký: Fewmoretaps OU d/b/a T….
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
Evidence Analysis
PhishDestroy identifies kanimex.com as an active brand impersonation domain targeting MEXC, designed to deceive users into connecting crypto wallets to a crypto-drainer kit. The domain was registered on April 09, 2026, and is currently leveraging a Let’s Encrypt SSL certificate to establish false legitimacy. Security telemetry indicates this domain has been weaponized to harvest funds through fraudulent transaction prompts, consistent with the operational patterns of modern crypto-draining campaigns.
Forensic analysis reveals exact technical indicators that reinforce its malicious classification: the domain resolves to IP address 172.67.147.202, carries a VirusTotal detection score of 8/95 security vendors, and is flagged by Hagezi DNS blocklists. The domain was registered through Fewmoretaps OU (d/b/a Trustname.com), a registrar frequently associated with low-friction, high-risk domain registrations. Additionally, it appears on one security blocklist and its recent creation date (April 09, 2026) suggests a hastily deployed threat actor resource. These attributes collectively confirm the domain’s role in a targeted impersonation campaign.
The domain remains active and continues to pose an elevated risk to users engaging with MEXC-related services. Immediate containment is advised: block kanimex.com at DNS and network levels, revoke SSL certificates via issuers where possible, and audit endpoints for wallet connection logs or drainer-related artifacts. Despite active detection by multiple vendors and blocklists, the risk remains significant due to the domain’s recent deployment and the growing sophistication of brand impersonation threats in the crypto sector. Ongoing monitoring and threat hunting are recommended to prevent potential financial loss.
Phạm vi dữ liệu14 recorded checks
Tình báo an ninh mạng Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | kanimex.com |
malicious | Sinkholed |
| DNS4EU | kanimex.com |
malicious | Sinkholed |
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Bản chụp đã lưu
Thông tin về tên miền
Chi tiết kỹ thuậtDNS, SAN trong SSL, dấu thời gian
ICANN OVERSIGHT
Bối cảnh công nhận và RAA
Bối cảnh công nhận và RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Lịch sử báo cáo lạm dụng · 7 stored reports over 15 days · click to expand
-
Report #2 ICANN CC 227h still active Apr 22, 2026 · 22:09 UTCESCALATION #2 (227h active): Phishing - kanimex[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 273h still active Apr 24, 2026 · 20:05 UTCESCALATION #3 (273h active): Phishing - kanimex[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #4 ICANN CC 318h still active Apr 26, 2026 · 17:08 UTCESCALATION #4 (318h active): Phishing - kanimex[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #5 ICANN CC 367h still active Apr 28, 2026 · 18:15 UTCESCALATION #5 (367h active): Phishing - kanimex[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #6 ICANN CC 429h still active May 1, 2026 · 07:38 UTCESCALATION #6 (429h active): Phishing - kanimex[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #7 ICANN CC 465h still active May 2, 2026 · 19:36 UTCESCALATION #7 (465h active): Phishing - kanimex[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #8 ICANN CC 567h still active May 7, 2026 · 01:51 UTCESCALATION #8 (567h active): Phishing - kanimex[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
Công nghệ · 4 identified
Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comPerformance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comPhân tích của VirusTotal
Phân tích hiệu suất trang
Google PageSpeed Insights — mobile performance audit of kanimex.com · checked Apr 13, 2026
Bằng chứng và các báo cáo bên ngoàiIndependent lookups and source reports
PD-20260413-E75D42 Recipient: abuse@trustname.com Victim safety and official reportingImmediate actions and verified reporting channels
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.