Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse-contact@publicdomainregistry.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
cryptomus-pay[.]cc
cryptomus-pay.cc 网络钓鱼与安全检查
“Crypto Exchange: Buy and Sell Cryptocurrencies Online | Cryptomus”
cryptomus-pay.cc — 最后已知的活跃状态 (HTTP 301). 诈骗类型:Crypto Drainer. 证据摘要: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 80/100. 注册商: PDR.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, cryptomus-pay.cc, is flagged as a crypto drainer threat specifically targeting users of the legitimate Cryptomus cryptocurrency exchange platform. Analysis indicates the domain was designed to impersonate the Cryptomus brand, likely employing a credential theft and wallet-draining mechanism to capture login credentials, API keys, or seed phrases from unsuspecting victims. The page title 'Crypto Exchange: Buy and Sell Cryptocurrencies Online | Cryptomus' closely mirrors the legitimate site, indicating a sophisticated brand impersonation campaign.
Infrastructure analysis reveals a VirusTotal detection rate of 5/95 security vendors flagging this domain as malicious. The domain was registered through PDR Ltd. d/b/a PublicDomainRegistry.com and resolves to IP address 188.114.97.3, which is associated with Cloudflare's infrastructure. The domain was created on February 21, 2026, with an SSL certificate issued by Google Trust Services. The domain appears on 1 security blocklist and is blocked by PhishDestroy. The Gridinsoft trust score is 0/100, indicating high risk. Technologies detected include Zendesk, Yandex.Metrika, Twitter Ads, reCAPTCHA, Mailgun, Google Tag Manager, Google Analytics, and Facebook Pixel, suggesting the threat actors employed multiple tracking and engagement tools.
Current status indicates the domain has been taken offline, reducing immediate risk. Response actions should include monitoring for similar domain registrations (e.g., variations of cryptomus-pay) and ensuring users are aware of the legitimate Cryptomus domain. Remaining risk includes potential re-registration under different TLDs or IP addresses, as well as the possibility that compromised credentials or wallets from active phishing campaigns have already been exfiltrated. Users who interacted with this domain should immediately rotate API keys, change passwords, and monitor cryptocurrency wallets for unauthorized transactions.
安全信号
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 9 identified
Customer support ticketing platform.
Conversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comGoogle's bot-challenge service. On phishing sites, used to appear legitimate and filter out automated scanners.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb analytics service tracking website traffic and user behavior.
marketingplatform.google.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comVirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of cryptomus-pay.cc · checked Jun 27, 2026
证据与外部报告
PD-20260207-A7958D Recipient: abuse-contact@publicdomainregistry.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。