bsquared[.]sbs
“bsquared.sbs | 504: Gateway time-out”
PhishDestroy identifies bsquared.sbs (registered March 31, 2026) as an active crypto drainer phishing domain designed to steal cryptocurrency assets by impersonating legitimate crypto services or platforms. The domain operates a fake login portal or transaction interface that silently drains wallets upon user interaction, typical of modern drainer kits leveraging social engineering and blockchain interaction prompts. The infrastructure includes a Let's Encrypt SSL certificate, suggesting an attempt to appear legitimate, and is hosted behind Cloudflare at IP 172.67.177.221, a common tactic to obscure origin and evade takedown efforts.
This domain exhibits multiple high-risk technical indicators. According to VirusTotal, only 2 out of 95 security vendors flagged bsquared.sbs as malicious as of the latest scan—indicating low early detection but high potential harm. The domain was registered through Dynadot LLC and has a recent creation date (March 31, 2026), which is suspicious given the lack of established reputation. While Google Safe Browsing (GSB) status is not specified, the low VT detection suggests it may not yet be widely blacklisted, increasing exposure to unsuspecting users. These factors point to a newly deployed, evolving threat designed to bypass initial security layers.
As of now, bsquared.sbs remains active with an elevated risk level, indicating ongoing malicious operations. PhishDestroy and participating threat intelligence networks continue to monitor and block this domain. Users are strongly advised not to interact with bsquared.sbs or any linked crypto transaction prompts. Due to the sophisticated nature of crypto drainers—often including fake wallet signatures or transaction approvals—the risk of irreversible financial loss is significant. Immediate network-level blocking is recommended for organizations, and personal users should verify URLs via trusted scanners before any interaction.
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
10 مصادر · تمت المزامنة في 10/08/2026
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
نطاق SHORTDOT · أدلة عامة
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات
تم تحديد 2 تقنيات بدرجة ثقة عالية
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب