bountyair[.]com
“$BOUNTY | Highest USDT Rewards”
ملخص الأدلة
The domain bountyair.com is identified as a crypto drainer phishing site, designed to deceive users into connecting wallets and siphoning cryptocurrency assets. Analysis confirms the domain is currently offline, though prior activity targeted individuals through fraudulent USDT reward schemes. No legitimate brand impersonation was detected; instead, the site operated under a fabricated incentive program labeled $BOUNTY to lure victims. Infrastructure analysis reveals the domain was registered on February 21, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, an uncommon creation date suggesting potential domain spoofing or preemptive registration. It resolved to the IP address 172.67.172.130, a Cloudflare-hosted endpoint leveraging HSTS and HTTP/3 protocols to obscure malicious activity. The domain appears on a single security blocklist and is flagged by 4 of 95 VirusTotal vendors, indicating limited but confirmed detection. A Gridinsoft trust score of 0/100 further corroborates its malicious classification. Current status confirms the domain has been taken offline, though residual risk remains for users who may have interacted with it prior to deactivation. Organizations and individuals are advised to block the domain and associated IP at the network level, monitor for wallet address reuse linked to this campaign, and conduct retrospective log analysis for connections to 172.67.172.130. Users should verify all cryptocurrency reward offers through official channels and enable hardware-based wallet protections to mitigate drainer threats. If credentials or wallet access were exposed, immediate revocation and asset migration to new addresses are recommended.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260124-B1E9C3
النص الكامل للدليل
Acceptable Use Policy (AUP): The domain bountyair.com is engaged in phishing activities, which directly contravenes your AUP prohibiting illegal activities and deception.
Terms of Service (TOS): The continued operation of this domain constitutes a violation of your TOS, which reserves the right to suspend or terminate services for any illegal or fraudulent activities.
Applicable Laws (SG):
Computer Misuse Act (Cap. 50A): This law prohibits unauthorized access and acts that cause harm to computer systems, including phishing.
Penal Code (Cap. 224) - Section 420: This section addresses cheating and dishonestly inducing delivery of property, which encompasses phishing schemes.
Electronic Transactions Act (Cap. 88): This act includes provisions against fraudulent electronic communications, specifically targeting phishing activities.
Regulatory Note: Failure to address this matter promptly may result in regulatory action against your organization for non-compliance with applicable laws and your own policies. Immediate action is recommended to mitigate potential legal repercussions.
Data Coverage
مؤشرات الأمان
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | bountyair.com/main.bbc2594c9c69111e.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
VirusTotal
1 ← 4
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب