bnqi[.]fi
“Benqi”
Riepilogo delle prove
The domain bnqi.fi is currently active and classified as a high‑risk brand impersonation campaign using a seed phishing technique. The site returns HTTP 200 and presents a page titled "Benqi," which is intended to mislead users into believing it is associated with the legitimate Benqi brand. The threat is confirmed as active as of July 12, 2026, and the risk level remains high due to its ongoing operation and the potential for credential harvesting.
Infrastructure analysis shows the domain was registered on March 11, 2026 through Immaterialism Ltd. It resolves to IP address 104.21.19.12, which belongs to AS13335 Cloudflare, Inc., and is located in the United States. DNS resolution is handled by the Cloudflare nameservers porter.ns.cloudflare.com and savanna.ns.cloudflare.com. The site uses a Let's Encrypt certificate (E8) providing TLS encryption, which may lend an appearance of legitimacy to unsuspecting victims.
Detection data indicates the domain appears on three security blocklists and has been flagged by one of ninety‑five security vendors on VirusTotal. Additionally, AlienVault OTX references the domain in two threat intelligence pulses, and it is actively blocked by PhishDestroy, MetaMask, and SEAL. While the low number of vendor detections suggests limited exposure, the presence on multiple blocklists and OTX pulses confirms that the domain is part of an observed malicious infrastructure.
Defenders should prioritize immediate blocking of bnqi.fi at network and endpoint layers, and enforce URL filtering to prevent user access. Continuous monitoring of DNS queries for the associated IP and Cloudflare nameservers is advised to detect potential pivot activity. Given the seed phishing nature of the campaign, security teams should also review logs for similar domain patterns and consider proactive threat hunting for related credential‑stealing attempts.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 10/08/2026
8 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo