boros-pendle.finance
“Rewards | Boros”
Analysis indicates that the domain boros-pendle.finance was registered on July 22, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
Analysis indicates that the domain boros-pendle.finance was registered on July 22, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. The authoritative name servers listed are coco.bunny.net and kiki.bunny.net, and DNS resolution points to the IPv4 address 62.60.226.88. Google Safe Browsing has classified the domain as a social‑engineering threat, and three independent blocklists (PhishDestroy, MetaMask, SEAL) have already listed it as malicious. The domain appears on a total of three security blocklists, reinforcing the assessment of high risk.
VirusTotal records show that the site has been examined by ninety‑five scanning engines; at the time of analysis none of the engines reported a detection, which does not constitute evidence of benign intent. The combination of recent creation, dedicated phishing‑oriented registrar information, use of generic bunny.net name servers, and immediate inclusion on multiple blocklists suggests a purpose‑built phishing infrastructure. The hosting IP 62.60.226.88 is currently active; no further attribution to an autonomous system or geographic location is provided in the available data.
Defenders should proactively block the domain and its resolving IP at network perimeters, incorporate the domain into URL filtering policies, and monitor for any outbound connections to the associated name servers. Continuous re‑scanning with multi‑vendor engines is recommended to detect any future changes in payload or malicious code. Given the high risk rating and active status, organizations handling credentials or financial transactions should treat any communication originating from this domain as potentially fraudulent.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Detection-evasion analysis
Cloaking and traffic-distribution check
Not yet scanned
No crawler-versus-browser difference has been recorded yet
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
Scanner note: timeout: raw=timeout; http=0; via=http_proxy; error=HTTPConnectionPool(host='142.147.129.126', port=5735): Read timed out. (read timeout=7)
Stored Capture · 2 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-23 02:38:20 UTC
Technologies · 4 identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of boros-pendle.finance · checked Jul 22, 2026
Lookalike domains
36 stored lookalike domains
Show all (24)
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive