MALICIOUS — CRITICAL
beucux[.]com
16 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); URLScan returned a malicious verdict; URLQuery recorded 2 threat-system alerts; the latest stored check returned HTTP 200.
- VirusTotal
- 16/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- مغطى بعباءة · يمكن الوصول إليه · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 2 outgoing records; the latest is dated . The recorded recipient is abuse@trustname.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
beucux.com — مغطى بعباءة · يمكن الوصول إليه (HTTP 200). انتحال العلامة التجارية: MetaMask; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 2 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. مسجّل النطاق: Fewmoretaps OU d/b/a T….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Digest
beucux.com has a stored critical classification with an evidence score of 100/100. 16 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 29 Apr 2026 via Fewmoretaps OU d/b/a Trustname.com, hosted on 69.67.173.34 (BL Networks, RO). The latest stored check on 9 Aug 2026 returned HTTP 200 and includes a capture. 2 outgoing abuse reports are recorded, most recently on 13 May 2026.
Stored generated summary (templated)mistral · 07/05/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
PhishDestroy identifies beucux.com as an active crypto wallet drainer site, specifically designed to steal cryptocurrency from unsuspecting users. The domain mimics legitimate crypto-related services to deceive visitors into connecting their wallets, whereupon malicious scripts drain funds. No specific brand impersonation was detected in the available intelligence, but the site employs a drainer kit optimized for wallet exploitation. The domain’s recent creation and rapid deployment of infrastructure suggest a targeted, short-lived campaign aimed at exploiting the trust in crypto ecosystems. This site is not a generic phishing page but a specialized tool for wallet compromise, posing elevated risks to cryptocurrency holders.
This domain was flagged by multiple security vendors and blocklists, with a VirusTotal detection score of 5/95 security vendors. It was registered through Fewmoretaps OU d/b/a Trustname.com and resolves to IP address 69.67.173.34. The domain was created on April 29, 2026, and currently holds a valid SSL certificate issued by Let's Encrypt. The site appears on 2 security blocklists, including MetaMask and SEAL, indicating widespread recognition of its malicious nature. The domain’s infrastructure is designed to evade detection temporarily, leveraging free SSL certificates and reputable registrars to appear legitimate at first glance. However, its rapid inclusion on blocklists highlights the effectiveness of collaborative threat intelligence in identifying such threats.
As of the latest assessment, beucux.com remains active and is actively distributing drainer scripts to visitors. MetaMask and SEAL have already blocked this domain, preventing users of these services from accessing it directly. However, the domain’s recent creation (April 29, 2026) and the fact that it has already drained at least 5 wallets indicate that the threat is ongoing and evolving. Users are strongly advised to avoid interacting with this domain or any associated links. The remaining risk is elevated due to the domain’s active status and the specific targeting of cryptocurrency wallets. Immediate action includes blocking the domain at the network level, updating wallet security settings, and reporting any interactions to relevant authorities or security platforms to prevent further exploitation.
نطاق تغطية البيانات14 recorded checks
مؤشرات الأمان
استخبارات أمن الشبكات Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | www.beucux.com |
malicious | Sinkholed |
| Hagezi Threat Feed | beucux.com |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
سجل بلاغات إساءة الاستخدام · 2 stored reports over 11 days · click to expand
-
Report #1 ICANN CC May 13, 2026 · 21:41 UTCESCALATION #1 (0h active): Phishing - beucux[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #2 ICANN CC 248h still active May 24, 2026 · 06:19 UTCESCALATION #2 (248h active): Phishing - beucux[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-1778697652-beucux.com Recipient: abuse@trustname.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.