bountyair[.]com
“$BOUNTY | Highest USDT Rewards”
Résumé des preuves
The domain bountyair.com is identified as a crypto drainer phishing site, designed to deceive users into connecting wallets and siphoning cryptocurrency assets. Analysis confirms the domain is currently offline, though prior activity targeted individuals through fraudulent USDT reward schemes. No legitimate brand impersonation was detected; instead, the site operated under a fabricated incentive program labeled $BOUNTY to lure victims. Infrastructure analysis reveals the domain was registered on February 21, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, an uncommon creation date suggesting potential domain spoofing or preemptive registration. It resolved to the IP address 172.67.172.130, a Cloudflare-hosted endpoint leveraging HSTS and HTTP/3 protocols to obscure malicious activity. The domain appears on a single security blocklist and is flagged by 4 of 95 VirusTotal vendors, indicating limited but confirmed detection. A Gridinsoft trust score of 0/100 further corroborates its malicious classification. Current status confirms the domain has been taken offline, though residual risk remains for users who may have interacted with it prior to deactivation. Organizations and individuals are advised to block the domain and associated IP at the network level, monitor for wallet address reuse linked to this campaign, and conduct retrospective log analysis for connections to 172.67.172.130. Users should verify all cryptocurrency reward offers through official channels and enable hardware-based wallet protections to mitigate drainer threats. If credentials or wallet access were exposed, immediate revocation and asset migration to new addresses are recommended.
Instantané des preuves transmises
- Envoyé
- Entrées du registre
- 1
- ID du dossier
PD-20260124-B1E9C3
Texte intégral des preuves
Acceptable Use Policy (AUP): The domain bountyair.com is engaged in phishing activities, which directly contravenes your AUP prohibiting illegal activities and deception.
Terms of Service (TOS): The continued operation of this domain constitutes a violation of your TOS, which reserves the right to suspend or terminate services for any illegal or fraudulent activities.
Applicable Laws (SG):
Computer Misuse Act (Cap. 50A): This law prohibits unauthorized access and acts that cause harm to computer systems, including phishing.
Penal Code (Cap. 224) - Section 420: This section addresses cheating and dishonestly inducing delivery of property, which encompasses phishing schemes.
Electronic Transactions Act (Cap. 88): This act includes provisions against fraudulent electronic communications, specifically targeting phishing activities.
Regulatory Note: Failure to address this matter promptly may result in regulatory action against your organization for non-compliance with applicable laws and your own policies. Immediate action is recommended to mitigate potential legal repercussions.
Data Coverage
Signaux de sécurité
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | bountyair.com/main.bbc2594c9c69111e.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
VirusTotal
1 → 4
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif