MALICIOUS — HIGH
binance[.]ooo[.]ec[.]cc
PhishDestroy identifies binance.ooo.ec.cc as an active binance brand impersonation domain currently under investigation.
- VirusTotal
- 1/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- لم يتم التحقق منها
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
binance.ooo.ec.cc — لم يتم التحقق منها. انتحال العلامة التجارية: Binance; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 1/91 (ESET); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
Is binance.ooo.ec.cc a Deceptive Binance Impersonation Domain?
The domain binance.ooo.ec.cc impersonates Binance, resolved to IP 154.36.188.124 and remains undetected.
PhishDestroy identifies binance.ooo.ec.cc as an active binance brand impersonation domain currently under investigation. This threat poses the highest immediate risk to users who may confuse the spoofed site for the legitimate Binance platform. The domain mimics Binance’s branding to harvest login credentials and sensitive data, with attackers banking on typographical and visual deception to trick visitors. The impersonated brand—Binance—is a top global cryptocurrency exchange, making the potential impact severe if users fall victim to credential theft or financial fraud.
Technical analysis reveals binance.ooo.ec.cc was registered via Gname.com Pte. Ltd., resolves to IP 154.36.188.124, and carries a valid Let's Encrypt SSL certificate. Importantly, VirusTotal currently shows 0 detections out of 95 engines, and public blocklists have not yet flagged the domain. The domain was created on October 13, 1997, an unusually early registration date that may indicate aged infrastructure repurposed for malicious intent. Despite no current detections, multiple red flags persist: the domain closely mimics Binance’s official branding, uses a subdomain structure (ooo.ec.cc) to appear authentic, and leverages HTTPS to appear legitimate.
This brand impersonation attack is designed to intercept user credentials and sensitive financial data by presenting a near-identical replica of Binance’s login portal. Users who access binance.ooo.ec.cc risk direct exposure of their Binance account details, potentially enabling unauthorized asset transfers or account takeover. To mitigate exposure, immediately block this domain at network and endpoint levels. Users should verify all platform access via the official Binance domain (binance.com) and enable two-factor authentication. Never click links from unsolicited emails or messages referencing this domain. Report any suspicious activity to Binance’s official security channels and update browser security settings to block newly identified impersonation domains. Exercise heightened vigilance when entering login credentials on any domain resembling binance.ooo.ec.cc.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org ثقة 100٪HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260504-182AB6 Recipient: complaint@gname.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.