MALICIOUS — CRITICAL
bounebit[.]io
PhishDestroy identifies bounebit.io as an active crypto drainer scam actively harvesting cryptocurrency wallet credentials and assets.
- VirusTotal
- 5/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- مغطى بعباءة · يمكن الوصول إليه · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bounebit.io — مغطى بعباءة · يمكن الوصول إليه (HTTP 301). انتحال العلامة التجارية: Raydium; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. مسجّل النطاق: Dynadot.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
PhishDestroy identifies bounebit.io as an active crypto drainer scam actively harvesting cryptocurrency wallet credentials and assets. This domain was flagged on December 17, 2025, and registered through Dynadot Inc, resolving to IP address 188.114.96.3. The domain operates with a legitimate Let's Encrypt SSL certificate to appear trustworthy while deploying deceptive wallet connection prompts that siphon funds to attacker-controlled addresses. This domain poses a significant threat by impersonating legitimate crypto services to trick users into connecting their wallets under false pretenses. Evidence supporting its malicious intent includes zero detections on VirusTotal (3/95 scanners) as of discovery, despite active deployment. The domain's recent creation date and hosting infrastructure suggest a hastily deployed operation designed to evade early detection systems. Users who interact with this domain risk irreversible cryptocurrency losses through automated fund transfers triggered by malicious smart contracts or browser extensions. If you visited bounebit.io, immediately revoke any wallet connections through your wallet provider's interface and transfer remaining assets to a clean wallet. Scan your device for malware using reputable security software and consider rotating all API keys and private credentials exposed during the session. Report the domain to your wallet provider and local cybercrime units to help disrupt this operation and protect other potential victims from similar crypto drainer attacks.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org ثقة 100٪Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org ثقة 100٪Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.