btcbull-snapshot[.]co
“404 Not Found”
btcbull-snapshot.co — No verificado. Suplantación de marca: Genericcrypto; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; PhishDestroy score 92/100. Registrador: OwnRegistrar.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of btcbull-snapshot.co as of July 23, 2026 indicates an active high‑risk crypto‑scam infrastructure. The domain was registered on February 21, 2026 through OwnRegistrar, Inc. and is currently resolved to the Cloudflare edge address 104.21.16.64, which belongs to AS13335 Cloudflare, Inc. in the United States. Authoritative nameservers are KELLY.NS.CLOUDFLARE.COM and ARTURO.NS.CLOUDFLARE.COM, confirming the use of Cloudflare’s DNS and CDN services; HTTP/3 is also observed. The site presents an HTTP 200 response while the HTML title is “404 Not Found”, suggesting a placeholder or intentionally obscured content. The TLS certificate is issued by Google Trust Services under the WE1 root, indicating a valid HTTPS connection but not mitigating the malicious intent.
Threat intelligence shows the domain appears on three security blocklists and has been flagged by multiple industry‑specific filters, including PhishDestroy, MetaMask, and SEAL. VirusTotal reports 13 of 93 scanners labeling the domain as malicious, and AlienVault OTX references the domain in one pulse. The classification provided is “Crypto Scam”, aligning with the broader generic phishing label. Despite these indicators, the exact payload or credential‑harvesting mechanisms have not been publicly disclosed, and the specific targeting vector remains uncertain.
Defenders should immediately add btcbull-snapshot.co to network‑level deny lists, enforce DNS sink‑hole routing, and monitor outbound connections to the Cloudflare address 104.21.16.64. Email gateways should block URLs containing the domain and any URLs that resolve to the same IP range. Incident response teams should treat any authentication attempts to crypto‑related services originating from this domain as compromised, and users should be warned to avoid providing private keys or wallet credentials. Continuous re‑evaluation is advised as further intelligence may emerge.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Tecnologías · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.