bs2siteat[.]net
“Blacksprut - это будущее!”
Détection enregistrée
Alerte de dissimulation
- Type de dissimulation
status_split- Score de dissimulation
- 2/6
Résumé des preuves
PhishDestroy has identified bs2siteat.net as a generic phishing domain masquerading under the Blacksprut brand. This domain, created on March 27, 2026, is designed to deceive users by impersonating the Blacksprut marketplace, potentially to harvest credentials or distribute malware. The page title "Blacksprut - это будущее!" further confirms the phishing narrative, though no specific drainer kit has been identified in this campaign.
Technical indicators provide critical insight into the domain's infrastructure. VirusTotal flagged it with 8 out of 95 security vendors, indicating moderate but notable detection. The domain is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to IP address 104.21.63.70. Its SSL certificate is issued by Google Trust Services (WE1). The domain currently appears on 1 security blocklist, and Google Safe Browsing status is not explicitly provided but inferred from the offline status. These markers collectively suggest a targeted phishing operation with a relatively low blocklist presence.
As of the latest analysis, bs2siteat.net has been taken offline, likely due to active mitigation by security teams or hosting providers. However, the risk remains elevated because similar domains may still be active. PhishDestroy advises users to avoid interacting with any Blacksprut-related links, especially those containing unusual domain structures. Users should verify URLs carefully and rely on official sources. Continued monitoring is recommended, as the infrastructure could be reactivated or variations may emerge.
Instantané des preuves transmises
- Envoyé
- Entrées du registre
- 1
- ID du dossier
PD-20260327-F30084- Titre de la page capturée
- Blacksprut - это будущее!
- Artefact PDF
- Preuve PDF
Texte intégral des preuves
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Preuves du résultat enregistrées
Résultat et attribution du retrait
- Résultat
inactive- Disponibilité
unreachable- Cause
registration_expired_redemption_period- Mécanisme
redemption_period- Confiance
- 95%
- Première observation
- Dernière observation
Indisponibilité estimée
Délai avant indisponibilité: 0 hSHA-256 de la preuve 5e4b5cf2d135
Chronologie de détection
-
Disponibilité
Première valeur enregistrée : DNS inactif
f93a11f87e4d -
Disponibilité
DNS inactif → Inconnu
adeb22973f6c -
Disponibilité
Inconnu → DNS inactif
38181f0d7434 -
Disponibilité
DNS inactif → Inactif
c49f81f96b02 -
Disponibilité
Inactif → DNS inactif
f52d526b76a1 -
Disponibilité
DNS inactif → Inconnu
fd2776ee0187 -
Disponibilité
Inconnu → Inactif
fe4244424d89 -
Disponibilité
Inactif → Inconnu
e6f74d08c80f -
Disponibilité
Inconnu → DNS inactif
6dfe9145995c -
Disponibilité
DNS inactif → Inactif
9f97161af11a
Tout afficher (12)
-
Disponibilité
Inactif → DNS inactif
641ed81dc4d5 -
Disponibilité
DNS inactif → Inconnu
60eb69b867d0 -
Disponibilité
Inconnu → Inactif
9f76f7c23fe3 -
Disponibilité
Inactif → Inconnu
bb0f084acd23 -
Disponibilité
Inconnu → DNS inactif
d0b7046e8c2f -
Disponibilité
DNS inactif → Inactif
1ada8f19325b -
Disponibilité
Inactif → DNS inactif
ca9ed662b468 -
Disponibilité
DNS inactif → Inconnu
7224b17d2b8c -
Disponibilité
Inconnu → Inactif
9a739243d539 -
Disponibilité
Inactif → DNS inactif
92f667ff6e00 -
Disponibilité
DNS inactif → Inconnu
4f2a4e11fd72 -
Disponibilité
Inconnu → Inactif
5e4b5cf2d135
Signalements communautaires
Signalé par 1 membre de la communauté ; première observation le 27/03/2026
- Signalements enregistrés
- 1
- URL signalées uniques
- 1
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse forensique
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of bs2siteat.net · checked Mar 28, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif