MALICIOUS — CRITICAL
bsb007-aus.com — Fake Login Phishing Investigation Report
bsb007-aus[.]
PhishDestroy identifies bsb007-aus.com as an active fake login phishing domain under investigation.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Disponibilidad
- Encubierto · accesible · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@trustname.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
bsb007-aus.com — Encubierto · accesible (HTTP 200). Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); cloaking observed; PhishDestroy score 86/100. Registrador: Fewmoretaps OU d/b/a T….
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
PhishDestroy identifies bsb007-aus.com as an active fake login phishing domain under investigation. This domain is designed to deceive users into entering credentials under false pretenses, posing a direct threat to online security. The threat remains active as further analysis is conducted to determine the full scope of its operations and potential victims.
This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating it has not yet been widely detected by security tools. It resolves to IP address 172.67.165.105 and was registered through Fewmoretaps OU d/b/a Trustname.com on January 22, 2026. The domain utilizes a Google Trust Services SSL certificate, adding a false sense of legitimacy, while its recent creation and low detection rate suggest it is a newly deployed threat. Despite its current lack of blocklist entries, users should remain cautious due to its active status and potential for rapid evolution.
While this domain is currently under investigation, users are strongly advised to avoid interacting with bsb007-aus.com and verify any suspicious links through PhishDestroy’s real-time threat intelligence platform. If exposure is suspected, immediately change passwords, enable two-factor authentication, and scan devices for malware. Security teams should monitor network traffic for connections to the associated IP address and consider blocking it at the firewall level. Remain vigilant as this threat may escalate in sophistication or expand its targeting as further intelligence emerges.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura de los datos12 recorded checks
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 10 identified
Strapi is an open-source headless CMS used for building fast and easily manageable APIs written in JavaScript.
strapi.io 100 % de confianzaNode.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100 % de confianzaReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100 % de confianzaNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100 % de confianzaExpress is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
expressjs.com 100 % de confianzaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % de confianzaCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100 % de confianzaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Datos y informes externosIndependent lookups and source reports
PD-20260428-12CCC6 Recipient: abuse@trustname.com Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.