binancezh[.]info
“Binance: The World’s Most Trusted Cryptocurrency Exchange to Buy, Trade”
Résumé des preuves
The domain www.binancezh.info was registered on March 13, 2026 through Gandi SAS and is presently active. DNS resolution points to IP 170.33.96.17, which belongs to ASN 134963 operated by Alibaba Cloud (Singapore) Private Limited. The server presents an SSL certificate issued to Alibaba Cloud Computing Ltd. and employs HSTS, indicating a legitimate‑looking TLS configuration. HTTP requests return a 302 redirect, and the page title advertises "Binance: The World’s Most Trusted Cryptocurrency Exchange to Buy, Trade," confirming a Binance brand impersonation. Infrastructure analysis reveals the use of Node.js, Express, Envoy, Google Sign‑in, Amazon Web Services, Amazon S3, and Google Tag Manager, suggesting a modern web stack. The domain appears on one security blocklist and has been blocked by PhishDestroy. VirusTotal scans show ten of ninety‑one security vendors flag the domain as malicious. The risk rating is high and the campaign is classified as a crypto scam. While the exact page content and any credential‑harvesting components have not been publicly disclosed, the combination of brand‑impersonating title, redirect behavior, and malicious vendor detections indicates a likely credential‑stealing operation targeting Binance users. Defenders should add the domain and its resolving IP to network and endpoint blocklists, monitor for DNS queries to the listed nameservers (ns-311.awsdns-38.com, ns-1212.awsdns-23.org, ns-651.awsdns-17.net, ns-16...), and enforce email and web filters that block URLs containing "binancezh.info." Incident response teams should advise users to verify Binance URLs through official channels and to avoid entering credentials on any site that redirects from this domain. Continuous observation of the IP address for changes in hosting or certificate details is recommended to detect potential migration of the phishing infrastructure.
Data Coverage
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | accounts.binancezh.info |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
VirusTotal
0 → 5
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif