MALICIOUS — HIGH
exchangepaygo[.]com
On July 22, 2026, analysis of exchangepaygo.com shows that the domain was registered on April 23, 2025 through Cosmotown, Inc.
- VirusTotal
- 6/95
- Blocklists
- No stored match
- 可用性
- 隐形 · 可达 · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
exchangepaygo.com — 隐形 · 可达 (HTTP 502). 品牌冒充:Facebook; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 6/95 (alphaMountain.ai, CyRadar, Fortinet, Kaspersky, Seclookup); cloaking observed; PhishDestroy score 68/100. 注册商: Cosmotown.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Analysis
exchangepaygo.com Fake Facebook Alert
Security analysis of exchangepaygo.com covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
On July 22, 2026, analysis of exchangepaygo.com shows that the domain was registered on April 23, 2025 through Cosmotown, Inc. The authoritative name server count is reported as one, and the domain resolves to the IPv4 address 198.12.80.250, which belongs to AS36352 operated by HostPapa in the United States. No TLS certificate was observed, indicating that the site was served over plain HTTP at the time of collection. The page title returned by the HTTP response is "Pi Blockchain, Community & Developer Platform | Pi Network", which aligns with the listed scam type of a crypto‑related scheme. The domain is flagged as a Facebook impersonation, suggesting that any luring content would reference the Facebook brand, although the exact landing page content has not been captured.
VirusTotal scans identified the domain as malicious in six out of ninety‑five vendor engines, and the domain appears on a single external security blocklist. PhishDestroy also listed the domain as blocked, reinforcing the malicious classification. Gridinsoft assigned a trust score of 0 out of 100, reflecting a lack of confidence in the host. The overall risk rating is elevated, and the infrastructure status is currently offline, indicating that the site has been taken down or is otherwise inaccessible.
While the available data confirms the registration details, hosting provider, IP location, lack of SSL, and the presence of multiple detection signals, the specific phishing kit, payload, or user‑facing artifacts remain unknown because the site was not captured while active. Analysts should continue to monitor the IP address 198.12.80.250 for any re‑use in future campaigns, and add exchangepaygo.com to internal blocklists and DNS sinkhole configurations. Defensive teams should also enforce strict outbound filtering for traffic to the identified IP range and educate users about unsolicited messages that claim to originate from Facebook but redirect to unrelated cryptocurrency content.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
数据覆盖范围12 recorded checks
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。