الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref 61BF3BF3

MALICIOUS — HIGH

binance[.]ooo[.]ec[.]cc

PhishDestroy identifies binance.ooo.ec.cc as an active binance brand impersonation domain currently under investigation.

66/100 evidence score · High
VirusTotal
1/91
Blocklists
2 · MetaMask, SEAL
التوفر
لم يتم التحقق منها
Report / Add Evidence Appeal this listing
2026-05-04 14:21 UTCلم يتم التحقق منها

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 1. قوائم الحظر العامة التي تبلغ عن تطابق: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is complaint@gname.com. The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
3 months
Reports sent
1
Latest case ID
PD-20260504-182AB6
Current status
Observed active at latest stored check
Jump to section
ملخص التقرير

binance.ooo.ec.cc — لم يتم التحقق منها. انتحال العلامة التجارية: Binance; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 1/91 (ESET); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. مسجّل النطاق: Gname.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref 61BF3BF3

Is binance.ooo.ec.cc a Deceptive Binance Impersonation Domain?

The domain binance.ooo.ec.cc impersonates Binance, resolved to IP 154.36.188.124 and remains undetected.

PhishDestroy identifies binance.ooo.ec.cc as an active binance brand impersonation domain currently under investigation. This threat poses the highest immediate risk to users who may confuse the spoofed site for the legitimate Binance platform. The domain mimics Binance’s branding to harvest login credentials and sensitive data, with attackers banking on typographical and visual deception to trick visitors. The impersonated brand—Binance—is a top global cryptocurrency exchange, making the potential impact severe if users fall victim to credential theft or financial fraud.

Technical analysis reveals binance.ooo.ec.cc was registered via Gname.com Pte. Ltd., resolves to IP 154.36.188.124, and carries a valid Let's Encrypt SSL certificate. Importantly, VirusTotal currently shows 0 detections out of 95 engines, and public blocklists have not yet flagged the domain. The domain was created on October 13, 1997, an unusually early registration date that may indicate aged infrastructure repurposed for malicious intent. Despite no current detections, multiple red flags persist: the domain closely mimics Binance’s official branding, uses a subdomain structure (ooo.ec.cc) to appear authentic, and leverages HTTPS to appear legitimate.

This brand impersonation attack is designed to intercept user credentials and sensitive financial data by presenting a near-identical replica of Binance’s login portal. Users who access binance.ooo.ec.cc risk direct exposure of their Binance account details, potentially enabling unauthorized asset transfers or account takeover. To mitigate exposure, immediately block this domain at network and endpoint levels. Users should verify all platform access via the official Binance domain (binance.com) and enable two-factor authentication. Never click links from unsolicited emails or messages referencing this domain. Report any suspicious activity to Binance’s official security channels and update browser security settings to block newly identified impersonation domains. Exercise heightened vigilance when entering login credentials on any domain resembling binance.ooo.ec.cc.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
1 det.
DNS Security
1/14
شهادة TLS
Let's Encrypt
العمر
3 mo
الحالة المرصودة
لم يتم التحقق منها
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات12 recorded checks
VirusTotal 1 / 91 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 1/14 TLS valid certificate, 85d WHOIS 3 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
DNS Provider Blocks 1 / 14
Brand Binance

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
13/14
Sent Report Recorded
Stored sent-report record for registrar Gname.com Pte. Ltd., hosting provider, 1 abuse contact
complaint@gname.com
04/05/2026

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN nginx · AS979 NetLab Global
سمعة عنوان IP abuse score 0/100 0 reports checked 13/07/2026
Registrar (base domain) Gname KY(KY)
جهة الإبلاغ عن إساءة الاستخدامcomplaint@gname.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ ec.cc →
عنوان IP 154.36.188.124 HK
الموقع الجغرافيHK Hong Kong, HK
الشبكةAS979 · NetLab Global
Registration (base domain)ec.cc · تم إنشاؤه 04/05/2026 (96d)
Elapsed Since First Report 7 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: لم يتم التحقق منها.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف04/05/2026
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://binance.ooo.ec.cc/
خوادم الأسماءb.rsp-dns.com
TLS Fingerprint
TLS Observationvalid from 30/04/2026scanned 04/05/2026
TLS SAN Domainscrypbex.io
Case ID
عنوان الصفحة
Crypbex.io
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 85 days
التقنيات · 3 identified
Nginx
Web servers Reverse proxies

Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.

nginx.org ثقة 100٪
HSTS
الأمن

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org ثقة 100٪
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org ثقة 100٪
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

1 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed
ESET
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/binance.ooo.ec.cc"
  title="PhishDestroy threat report for binance.ooo.ec.cc"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>