Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 2 outgoing records; the latest is dated . The recorded recipient is abuse@trustname.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
beucux[.]com
beucux.com की फ़िशिंग और सुरक्षा जाँच
beucux.com — ढका हुआ · पहुंच योग्य (HTTP 200). ब्रांड प्रतिरूपण: MetaMask; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 2 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. रजिस्ट्रार: Fewmoretaps OU d/b/a T….
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
PhishDestroy identifies beucux.com as an active crypto wallet drainer site, specifically designed to steal cryptocurrency from unsuspecting users. The domain mimics legitimate crypto-related services to deceive visitors into connecting their wallets, whereupon malicious scripts drain funds. No specific brand impersonation was detected in the available intelligence, but the site employs a drainer kit optimized for wallet exploitation. The domain’s recent creation and rapid deployment of infrastructure suggest a targeted, short-lived campaign aimed at exploiting the trust in crypto ecosystems. This site is not a generic phishing page but a specialized tool for wallet compromise, posing elevated risks to cryptocurrency holders.
This domain was flagged by multiple security vendors and blocklists, with a VirusTotal detection score of 5/95 security vendors. It was registered through Fewmoretaps OU d/b/a Trustname.com and resolves to IP address 69.67.173.34. The domain was created on April 29, 2026, and currently holds a valid SSL certificate issued by Let's Encrypt. The site appears on 2 security blocklists, including MetaMask and SEAL, indicating widespread recognition of its malicious nature. The domain’s infrastructure is designed to evade detection temporarily, leveraging free SSL certificates and reputable registrars to appear legitimate at first glance. However, its rapid inclusion on blocklists highlights the effectiveness of collaborative threat intelligence in identifying such threats.
As of the latest assessment, beucux.com remains active and is actively distributing drainer scripts to visitors. MetaMask and SEAL have already blocked this domain, preventing users of these services from accessing it directly. However, the domain’s recent creation (April 29, 2026) and the fact that it has already drained at least 5 wallets indicate that the threat is ongoing and evolving. Users are strongly advised to avoid interacting with this domain or any associated links. The remaining risk is elevated due to the domain’s active status and the specific targeting of cryptocurrency wallets. Immediate action includes blocking the domain at the network level, updating wallet security settings, and reporting any interactions to relevant authorities or security platforms to prevent further exploitation.
सुरक्षा संकेत
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | www.beucux.com |
malicious | Sinkholed |
| Hagezi Threat Feed | beucux.com |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
दुरुपयोग रिपोर्ट इतिहास · 2 stored reports over 11 days · click to expand
-
Report #1 ICANN CC May 13, 2026 · 21:41 UTCESCALATION #1 (0h active): Phishing - beucux[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #2 ICANN CC 248h still active May 24, 2026 · 06:19 UTCESCALATION #2 (248h active): Phishing - beucux[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-1778697652-beucux.com Recipient: abuse@trustname.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।