# PhishDestroy threat dossier — bicielettrica.shop ================================================================ Fetched: 2026-07-22 14:07:56 UTC Canonical: https://phishdestroy.io/domain/bicielettrica.shop/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 55/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 9/94 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, Cluster25, CyRadar, Fortinet, G-Data, Gridinsoft, MalwareURL Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 93.186.249.90 (IT, Arezzo) ASN: AS31034 Aruba S.p.A. Hosting org: Aruba S.p.A. - Cloud Services Registrar: Dynadot Inc. Nameservers: ["ns1.dyna-ns.net", "ns2.dyna-ns.net"] Registered: 2026-04-22 Page title: Bici Elettrica Shop: consigli e offerte sul mondo dell'e-bike ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-06-01 Status: INVALID chain Fingerprint: 93f8a3df691e397702b4966c833259e6ee5d2de178d2167d83c8185da04cee0a Subject Alternative Names (related infrastructure — often same operator): - www.bicielettrica.shop ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-22 18:00:12 UTC (by PhishDestroy tracker) First reported: 2026-06-15 00:27:29 UTC (abuse notice filed) Last verified: 2026-07-22 12:20:56 UTC Neutralised: 2026-04-23 02:13:54 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLQuery: https://urlquery.net/report/07805d98-c780-475b-b1b5-a279d77a1537 Wayback Machine: https://web.archive.org/web/*/bicielettrica.shop crt.sh CT logs: https://crt.sh/?q=%25.bicielettrica.shop Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=bicielettrica.shop AlienVault OTX: https://otx.alienvault.com/indicator/domain/bicielettrica.shop URLhaus: https://urlhaus.abuse.ch/host/bicielettrica.shop/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-26 15:11:13 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] bicielettrica.shop — Fake E-Bike Retailer Phishing Investigation This domain, bicielettrica.shop, poses as a legitimate e-bike retailer to conduct brand impersonation phishing attacks targeting consumers in the Italian market. Analysis indicates the site mimics authentic e-commerce platforms, likely harvesting payment details, personal information, or login credentials under the guise of offering e-bike advice and promotions. The fraudulent infrastructure is designed to exploit trust in well-known retail brands, presenting a significant risk to users seeking genuine products or deals online. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain is flagged by 9 out of 95 security vendors on VirusTotal, including detection as a phishing threat. It is registered through Dynadot Inc. and was created on April 22, 2026, suggesting a recent and potentially short-lived deployment typical of phishing campaigns. The domain resolves to IP address 93.186.249.90, hosted on infrastructure belonging to an Italian cloud provider, and appears on one security blocklist. The site employed a Let's Encrypt SSL certificate (R12), which, while providing encryption, does not validate the legitimacy of the underlying operation. Users who visited bicielettrica.shop are advised to take immediate remedial action to mitigate potential compromise. Any credentials, payment information, or personal details entered on the site should be considered exposed and must be changed across all platforms where reused. Affected individuals should monitor financial statements for unauthorized transactions and enable multi-factor authentication on critical accounts. Browser-based password managers may have auto-filled sensitive data; users should review stored credentials and remove any associated with this domain. Given the elevated risk level and confirmed offline status, this domain is unlikely to be reactivated under the same name, but similar threats may emerge using comparable naming conventions or infrastructure. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: ec5ee2323fddafc612324d91c2883461 TLS cert SHA-256: 93f8a3df691e397702b4966c833259e6ee5d2de178d2167d83c8185da04cee0a ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/bicielettrica.shop/ JSON API: https://api.destroy.tools/v1/check?domain=bicielettrica.shop Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,091 domains (57,536 alive under monitoring, 128,922 confirmed takedowns/dead). Site: https://phishdestroy.io