binance[.]consumerhelpline[.]net
“Binance Customer Support”
binance.consumerhelpline.net — Contenu indisponible. Usurpation de l'identité de la marque : Binance; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 5/94 (CyRadar, Fortinet, G-Data, SOCRadar, Sophos); Spamhaus DBL_PHISH; PhishDestroy score 65/100. Bureau d’enregistrement: Ultahost.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of binance.consumerhelpline.net shows a newly registered domain created on 11 March 2026 through Ultahost, Inc. The domain resolves to the IPv4 address 82.25.34.79, which belongs to AS212238 Datacamp Limited and is geolocated in Norway. The hosting infrastructure is served by Apache HTTP Server and uses the authoritative nameservers ns1.ultahost.com through ns4.ultahost.com. The site’s HTTP response previously presented the page title “Binance Customer Support”, directly referencing the Binance brand, and the overall classification is a crypto‑scam that relies on brand impersonation. VirusTotal scans reported five detections out of ninety‑four security vendors, indicating that multiple AV engines identified the domain as malicious.
The domain is listed on one external security blocklist and has been actively blocked by the PhishDestroy mitigation service. The current operational status is offline, suggesting that the phishing infrastructure has been taken down or is no longer serving content. Evidence confirms the use of the Binance brand without authorization, satisfying the definition of brand impersonation. The short lifespan of the domain, combined with the modest detection count, may indicate a low‑volume campaign targeting Binance users.
Uncertainties remain regarding the presence of SSL/TLS certificates, the exact payload delivered to victims, and whether additional supporting infrastructure exists elsewhere. Defenders should continue to monitor the IP address 82.25.34.79 for any re‑use, enforce blocking of the domain and its associated IP in network perimeter defenses, and add the domain to internal phishing and malware blocklists. Organizations using Binance services should alert users to the existence of this impersonating site and advise verification of URLs before entering credentials. Ongoing vigilance through threat‑intel feeds and periodic re‑scanning of the domain, should it become active again, is recommended.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Registration: consumerhelpline.net
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain consumerhelpline.net behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 1 identified
Most widely used open-source HTTP server software.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of binance.consumerhelpline.net · checked Mar 17, 2026
Données factuelles et rapports externes
PD-20260317-A665B5 Recipient: abuse@ultahost.com Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif