bnbguy[.]info
Verifica phishing e sicurezza per bnbguy.info
“LaunchTool: No-Code Solana Token Creator for Crypto Projects - Launchtool”
bnbguy.info — Ammantato · raggiungibile (HTTP 404). Simulazione del marchio: Solana; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 5/91 (ADMINUSLabs, alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. Registrar: Dynadot.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
This domain bnbguy.info was registered on May 07 2026 through Dynadot Inc. It resolves to the Cloudflare‑owned address 172.67.163.15, which is geo‑located in Canada. The authoritative nameservers are kay.ns.cloudflare.com and trey.ns.cloudflare.com, and the site presents a valid SSL certificate issued by Google Trust Services (WE1). The domain appears on three public blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL. AlienVault OTX records a single threat‑intel pulse referencing bnbguy.info, and VirusTotal reports that five of ninety‑five scanned security vendors have flagged the site. Gridinsoft assigns a trust score of 0 out of 100, indicating a high confidence of malicious intent. The page title displayed by the site—“LaunchTool: No‑Code Solana Token Creator for Crypto Projects – Launchtool”—explicitly references Solana and mimics a legitimate token‑creation service. This page advertises a no‑code tool for launching Solana tokens, a classic vector for brand impersonation aimed at deceiving developers or investors seeking to create or purchase Solana‑based assets. The combination of a high‑profile brand name, a plausible service description, and the presence on multiple blocklists suggests a targeted impersonation campaign rather than a benign informational site. Given the high‑risk rating, defenders should block DNS resolution for bnbguy.info at network perimeters and add the domain to web‑filter allow‑deny lists. Continuous monitoring of the IP address 172.67.163.15 for any changes in hosting or certificate details is advised, as Cloudflare infrastructure can be repurposed by malicious actors. Security teams should also update endpoint protection signatures to incorporate the five VirusTotal‑detected detections and consider sharing the indicator set with threat‑intel communities to improve collective awareness.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.