Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@v-sys.org.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
xmr-mixer[.]to
“Monero Mixer | XMR Tumbler | Best Monero Blender - Secure & Anonymous”
xmr-mixer.to — 未验证. 证据摘要: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 2 alerts; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 100/100. 注册商: Government of Kingdom ….
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, xmr-mixer.to, is actively flagged as a high-risk Monero cryptocurrency laundering phishing site. Analysis indicates the domain was registered on February 21, 2026, through the Government of the Kingdom of Tonga registrar. The site resolves to IP address 176.97.124.200, hosted under AS6698 (Virtual Systems LLC) in Ukraine, and employs Nginx with HSTS enabled. The SSL certificate is issued by Let's Encrypt (R12), and the HTTP response status is 200, confirming operational accessibility.
The page title, 'Monero Mixer | XMR Tumbler | Best Monero Blender - Secure & Anonymous,' explicitly advertises cryptocurrency mixing services, a common vector for phishing and money laundering. The domain appears on four security blocklists and has been documented in 13 AlienVault OTX threat intelligence pulses, indicating widespread detection by the security community. Sixteen of 95 security vendors on VirusTotal flag this domain as malicious. Specific blocking services include PhishDestroy, Polkadot, Enkrypt, and Codeesura.
Infrastructure analysis reveals the domain uses nameservers ns1.zomro.net and ns2.zomro.ru, and Gridinsoft assigns a trust score of 0/100. While the exact content and functionality of the site remain unconfirmed, the combination of cryptocurrency-related branding, active blocklist presence, and low trust scores strongly suggests malicious intent. Defenders should treat this domain as a confirmed threat, block access at the network level, and monitor for related transactions or user interactions involving Monero or XMR addresses.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of xmr-mixer.to · checked Mar 1, 2026
证据与外部报告
PD-20260125-3E58F7 Recipient: abuse@v-sys.org 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。