# bs2bestbs.net — SUSPICIOUS > bs2bestbs.net hosts a generic phishing page mimicking Cash App for credential theft. Add to blocklists; 0/95 VirusTotal detections as of seed 18b9f0. ## Summary PhishDestroy identifies bs2bestbs.net as an active generic phishing domain currently under investigation for Cash App brand impersonation. The site is operational and poses a credible threat to users tricked into entering login details. Domain registration and hosting infrastructure align with known phishing tactics, warranting immediate scrutiny. This domain was flagged by zero of 95 VirusTotal vendors, indicating it has yet to be blacklisted despite its malicious nature. It was registered on January 21, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to IPv4 address 104.21.80.169. The SSL certificate, issued by Google Trust Services, suggests an attempt to appear legitimate. Additional monitoring is advised due to the lack of detections and high-risk timeline. Current status remains active, with no confirmations of takedowns or remediations. SOC teams are urged to block bs2bestbs.net at the network perimeter and DNS level. Users should be warned against interacting with Cash App-themed links from untrusted sources. Further IOCs include the IP and registrar details; adjust security policies to flag or quarantine traffic to this domain. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-01-21 17:24:18 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 104.21.80.169 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/16c6ee8b-9881-4f33-a2d3-899f86b37b09 - PhishDestroy: https://phishdestroy.io/domain/bs2bestbs.net/ - LLM endpoint: https://phishdestroy.io/domain/bs2bestbs.net/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/bs2bestbs.net/ Last updated: 2026-03-27