bbwukjih[.]dnq[.]r[.]110880[.]cn
“TikTok”
bbwukjih.dnq.r.110880.cn — Contenu indisponible. Usurpation de l'identité de la marque : TikTok; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 17/93 (Criminal IP, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 95/100. Bureau d’enregistrement: Dynadot.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis indicates that the domain bbwukjih.dnq.r.110880.cn was registered on August 2, 2025 through Dynadot LLC and is currently taken offline. The domain resolves to the IPv4 address 38.46.13.34, which is announced by AS9294 GNET INC. and geolocated to Hong Kong. No TLS certificate is presented, meaning the site would have been served over plain HTTP only. The page title returned from the host is “TikTok”, matching the declared brand target of TikTok and confirming a brand‑impersonation motive.
Google Safe Browsing has flagged the domain for social engineering, and Gridinsoft assigns a trust score of 0 out of 100, indicating a high likelihood of malicious intent. VirusTotal reports that 17 out of 93 scanning engines have identified the domain as malicious, reinforcing the suspicion. The domain is listed on a single security blocklist and has been actively blocked by PhishDestroy. Nameserver records point to ns1.dnsip.com and ns2.dnsip.com, which are commonly used by disposable or fast‑flux services.
The combination of a recent registration, lack of encryption, low trust score, multiple vendor detections, and explicit brand targeting provides concrete evidence that the domain was employed for brand‑impersonation attacks against TikTok users. Uncertainty remains regarding the exact payload or credential‑harvesting mechanisms because the site content has not been captured; however, the existing indicators are sufficient for defensive actions. Organizations should add the domain to internal blocklists, monitor DNS queries for the associated IP and nameservers, and ensure that web filtering solutions incorporate the Google Safe Browsing and PhishDestroy classifications. Continuous re‑scanning of the IP address is advised in case the domain becomes active again.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif