This domain, bonk-bot.xyz, was registered on July 02, 2026 through NameSilo, LLC and is currently resolved to the IPv4 address 186.2.175.35. The authoritative name servers are ns1.dnsowl.com, ns2.dnsowl.com, and ns3.dnsowl.com. Threat intelligence classifies the site as a generic phishing operation with a high risk rating. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy service. VirusTotal analysis shows that 1 of 91 scanned security vendors flagged the domain, indicating at least one detection of malicious behavior.
No additional public blocklists or safe‑browsing services are listed in the supplied data. The domain remains “active” as of the report date, July 30, 2026, and no evidence of takedown or remediation has been reported. Observations confirm that the domain’s age is less than one month, which is consistent with rapid‑deployment phishing campaigns. The use of DNS Owl name servers, a provider that hosts many unrelated legitimate sites, does not by itself imply malicious intent, but the combination of recent registration, single‑vendor detection, and blocklist inclusion strengthens the suspicion.
Because the site’s content, SSL certificate details, HTTP response codes, and page title have not been disclosed, the exact phishing payload and targeted brand remain unknown. Defenders should add bonk-bot.xyz to inbound and outbound filtering rules, enforce DNS sink‑hole or blocklist controls for the address 186.2.175.35, and monitor NameSilo‑registered domains for similar patterns. Continuous re‑scanning on VirusTotal and other multi‑engine platforms is recommended to capture any new detections. Incident response teams should treat any user interaction with this domain as compromised and initiate credential reset procedures if credentials were entered.