btcbultolkens[.]com
“Account Suspended”
ملخص الأدلة
The domain btcbultolkens.com was registered on July 06, 2025 through GoDaddy.com, LLC and currently resolves to the IPv4 address 198.12.66.123, which belongs to AS36352 HostPapa and is geolocated in the United States. The site presents a TLS certificate issued by GoDaddy TLS Intermediate CA DV, confirming that the certificate chain is valid and that the domain is using a standard SSL provider. An HTTP request to the host returns a 200 status code and the page title is "Account Suspended," indicating that the content displayed is a generic suspension notice rather than a functional service.
The domain is listed on four external security blocklists and has been actively blocked by multiple anti‑phishing services, including PhishDestroy, Polkadot, Enkrypt, and Codeesura. VirusTotal analysis shows that two of ninety‑five security vendors have flagged the domain, providing additional corroboration of malicious intent. The threat classification associated with the domain is "Account Takeover," suggesting that attackers may be attempting to harvest credentials or hijack user accounts, although the exact target brand or service is not disclosed in the available data.
Defenders should treat the domain as high‑risk: ingest the domain into DNS sinkhole or blocklist configurations, enforce outbound traffic filtering for the resolved IP, and monitor TLS handshake logs for connections to the GoDaddy‑issued certificate. Alerting on any user‑initiated connections to the host, especially from internal workstations, will help contain potential credential‑theft attempts. Continuous re‑evaluation is advised, as the current evidence is limited to registration details, hosting infrastructure, and blocklist presence; further investigation of request patterns and any associated payloads would clarify the full scope of the campaign.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
٧ مصادر خارجية مراقبة لا تطابق
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة المؤرشفة
تحليل إعدادات الموقع
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب