binexbit[.]com
“Cryptocurrency Exchange – binexBIT”
This domain is flagged as an elevated-risk credential theft operation targeting cryptocurrency users. Analysis indicates the site impersonates a legitimate cryptocurrency exchange platform, likely designed to harvest login credentials, private keys, or other sensitive authentication details from victims. The threat type is specifically credential theft, with potential secondary risks including cryptocurrency wallet compromise or unauthorized fund transfers. Infrastructure analysis reveals the domain binexbit.com was registered on May 20, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. The domain resolves to the IP address 104.21.55.106, which is proxied through Cloudflare, obscuring the true origin of the malicious infrastructure. Detection metrics show the domain is flagged by 9 out of 95 security vendors on VirusTotal, while Gridinsoft assigns a trust score of 0 out of 100. The domain appears on three security blocklists and is actively blocked by MetaMask, PhishDestroy, and SEAL threat intelligence feeds. Technologies detected include Node.js, Vue.js, Nuxt.js, Nginx, Express, and reCAPTCHA, suggesting a sophisticated frontend designed to mimic legitimate exchange platforms. Mitigation steps for this specific threat type include immediate verification of exchange URLs through official sources before entering credentials. Users should enable multi-factor authentication on all cryptocurrency accounts and employ hardware security keys where possible. Network-level protections should block the domain and associated IP address 104.21.55.106 across all security gateways. Organizations should monitor for credential reuse attempts from harvested accounts and implement strict validation procedures for cryptocurrency withdrawal requests. Given the domain's current offline status, security teams should remain vigilant for re-emergence under similar naming conventions or infrastructure.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | binexbit.com/app-resources-d6/main.c71c8c5d3e740df2e460.v2.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 स्रोत · 09/08/2026 को सिंक किया गया
परिणाम के संग्रहीत प्रमाण
परिणाम और टेकडाउन श्रेय
- परिणाम
held- कारण
registrar_client_hold- कार्रवाईकर्ता
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- तंत्र
client_hold- विश्वसनीयता
- 95%
रजिस्ट्रार की कार्रवाई
NICENIC INTERNATIONAL GROUP CO., LIMITED IANA 3765
श्रेय के प्रमाण:
अनुमानित अनुपलब्धता
अनिश्चितता अवधि: ±1107.7 h समय की सटीकता:very_low पहचान समयरेखा
संग्रहीत अवलोकन कालानुक्रमिक क्रम में।
-
VirusTotal
VirusTotal: 2 → 9
-
उपलब्धता
उपलब्धता: पहली बार dns_inactive के रूप में देखा गया
f93a11f87e4d -
उपलब्धता
उपलब्धता: dns_inactive → unknown
7d4c104259da -
उपलब्धता
उपलब्धता: unknown → dns_inactive
765cd006da9f -
उपलब्धता
उपलब्धता: dns_inactive → held
43527fe452c6 -
उपलब्धता
उपलब्धता: held → dns_inactive
f52d526b76a1 -
उपलब्धता
उपलब्धता: dns_inactive → unknown
d1ee947a454f -
उपलब्धता
उपलब्धता: unknown → held
60f8f0544f9c -
उपलब्धता
उपलब्धता: held → unknown
a419c0b75a84 -
उपलब्धता
उपलब्धता: unknown → dns_inactive
6dfe9145995c
सभी दिखाएँ (7)
-
उपलब्धता
उपलब्धता: dns_inactive → held
87406831db74 -
उपलब्धता
उपलब्धता: held → dns_inactive
641ed81dc4d5 -
उपलब्धता
उपलब्धता: dns_inactive → unknown
3dffb2633088 -
उपलब्धता
उपलब्धता: unknown → held
3368a5979fa5 -
उपलब्धता
उपलब्धता: held → unknown
f0a5e2eba586 -
उपलब्धता
उपलब्धता: unknown → dns_inactive
d0b7046e8c2f -
उपलब्धता
उपलब्धता: dns_inactive → held
fdcc1011b72c
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें
9 उच्च-विश्वसनीयता वाली तकनीकें पहचानी गईं
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।