MALICIOUS — CRITICAL
keymine.cc 网络钓鱼与安全检查
keymine[.]
Analysis of keymine.cc indicates a deliberate brand impersonation campaign targeting Ethereum users.
- VirusTotal
- 5/95
- Blocklists
- No stored match
- 可用性
- 内容不可用 · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
keymine.cc — 内容不可用 (HTTP 502). 品牌冒充:Ethereum; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 5/95 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 70/100. 注册商: CSL Computer Service L….
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Analysis
Analysis of keymine.cc indicates a deliberate brand impersonation campaign targeting Ethereum users. The domain was registered on October 15, 2025 through CSL Computer Service Langenbach GmbH d/b/a joker.com and is currently hosted on IP address 185.186.55.26, which resolves to an AS209003 Genius Guard network located in France. The site presented the page title "Keymine — AI Trading + GPU/LPU Mining for Automated Yield," a phrasing that aligns with cryptocurrency mining services and is likely intended to attract investors or miners by mimicking legitimate crypto offerings.
No SSL certificate was observed, and the HTTP service returned an offline status at the time of analysis, suggesting the operator may have taken the site down after initial distribution. The domain employs four authoritative name servers (ns1.easy-geo-dns.com through ns4.easy-geo-dns.com), a configuration commonly seen in disposable or fast‑flux infrastructures used for phishing or scam campaigns. Security assessments show the domain appears on a single blocklist, PhishDestroy, and received five detections out of ninety‑five scanners on VirusTotal, reinforcing the suspicion of malicious intent.
Additionally, Gridinsoft assigned a trust score of 1 out of 100, indicating a high likelihood of abuse. Defenders should immediately block keymine.cc at DNS and proxy layers, monitor for related CNAME or IP aliases, and consider adding the associated IP range to threat‑intel feeds. Continuous re‑scanning is advised, as the offline status may change if the operators reactivate the site for further distribution.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
数据覆盖范围13 recorded checks
安全信号
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。