bonkrewards[.]io
“Bonk Rewards”
Riepilogo delle prove
Analysis of bonkrewards.io, reported on July 22, 2026, shows an elevated‑risk infrastructure that aligns with a fake‑airdrop campaign impersonating the foundation brand. The domain was registered on August 22, 2025 through GoDaddy.com, LLC and is delegated to the Cloudflare nameservers achiel.ns.cloudflare.com and delilah.ns.cloudflare.com. DNS resolution points to the IP address 104.21.24.171, which belongs to AS13335 Cloudflare, Inc., located in the United States. The web server presents a TLS certificate issued by Google Trust Services under the WE1 root, indicating a valid‑looking HTTPS endpoint, and the service advertises modern protocols such as HTTP/3 and enforces HSTS, suggesting a deliberately hardened front‑end.
Backend technology fingerprints reveal a Node.js environment running Express, a stack commonly abused for rapid deployment of malicious pages. An HTTP request to the site returns a 403 status code, and the domain is currently taken offline, consistent with takedown or temporary suspension. Threat intelligence flags the domain on two blocklists, specifically PhishDestroy and ScamSniffer, and VirusTotal reports three positive detections out of ninety‑five scanners, reinforcing the malicious classification. The page title "Bonk Rewards" does not match the targeted foundation brand, yet the intelligence explicitly lists the brand impersonated as foundation, confirming a credential‑harvesting or reward‑fraud motive.
Defenders should block traffic to 104.21.24.171 and any associated CNAMEs, enforce DNS sinkholing for the domain, and monitor for similar Cloudflare‑hosted nodes that present Node.js/Express stacks with HSTS and HTTP/3. Additional remediation steps include updating web‑gateway filters with the observed blocklist identifiers, and correlating logs for attempts to access the "Bonk Rewards" title or related URL patterns.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
9 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Stato del dominio
Non raggiungibile → Raggiungibile
Segnalazioni della comunità
Segnalato da 1 membro della comunità; prima osservazione il 28/10/2025
- Segnalazioni memorizzate
- 1
- URL segnalati univoci
- 1
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo