changeenow[.]at
“Instant Cryptocurrency Exchange | Best Rates & Lowest Fees | ChangeNOW”
changeenow.at — 未验证. 品牌冒充:Across; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 17/91 (ADMINUSLabs, alphaMountain.ai, AlphaSOC, BitDefender, Chong Lua Dao); Spamhaus DBL_PHISH; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 100/100. 注册商: CSL Computer Service L….
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
On July 23 2026, the domain changeenow.at was observed hosting a page titled “Instant Cryptocurrency Exchange | Best Rates & Lowest Fees | ChangeNOW”. The page title indicates a direct attempt to impersonate the ChangeNOW brand, a known cryptocurrency exchange service. Technical analysis shows the domain is served from the IP address 62.60.226.213, which belongs to AS214351 (FEMO IT SOLUTIONS LIMITED) located in Germany. The domain is delegated to Cloudflare name servers desiree.ns.cloudflare.com and ethan.ns.cloudflare.com, but no TLS certificate is present, meaning the site was reachable only over plain HTTP.
Registration records list CSL Computer Service Langenbach GmbH as the registrar, confirming a legitimate Austrian registrar was used. Reputation services assign a Scamadviser score of 1/100 and a Gridinsoft score of 0/100, indicating extreme distrust. The domain appears on four public blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—and is referenced in sixteen AlienVault OTX pulses, reflecting multiple threat‑intel sources that have previously flagged the same infrastructure. VirusTotal scans show sixteen of ninety‑five antivirus engines flag the domain as malicious, reinforcing the suspicion of fraudulent activity.
The site is currently taken offline, but historical evidence suggests it was used for brand impersonation to lure victims seeking cryptocurrency services. Uncertainty remains regarding any active payloads, credential‑harvesting forms, or redirects that may have been present while the site was live, as no page content beyond the title has been captured. Defenders should continue to block the DNS name and associated IP address, monitor for any resurgence of the domain or similar look‑alike registrations, and incorporate the listed indicators into intrusion‑detection and web‑filtering rules. Additional vigilance is advised for traffic targeting ChangeNOW users, especially requests to the now‑inactive changeenow.
安全信号
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。