MALICIOUS — HIGH
Verifica phishing e sicurezza per bsquared.sbs
bsquared[.]
PhishDestroy identifies bsquared.sbs (registered March 31, 2026) as an active crypto drainer phishing domain designed to steal cryptocurrency assets by impersonating legitimate crypto services or platforms.
- VirusTotal
- 4/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Contenuto non disponibile · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bsquared.sbs — Contenuto non disponibile (HTTP 404). Tipo di truffa: Crypto Drainer. Riepilogo delle prove: VirusTotal 4/91 (Bfore.Ai PreCrime, Gridinsoft, SOCRadar, Webroot); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: Dynadot.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy identifies bsquared.sbs (registered March 31, 2026) as an active crypto drainer phishing domain designed to steal cryptocurrency assets by impersonating legitimate crypto services or platforms. The domain operates a fake login portal or transaction interface that silently drains wallets upon user interaction, typical of modern drainer kits leveraging social engineering and blockchain interaction prompts. The infrastructure includes a Let's Encrypt SSL certificate, suggesting an attempt to appear legitimate, and is hosted behind Cloudflare at IP 172.67.177.221, a common tactic to obscure origin and evade takedown efforts.
This domain exhibits multiple high-risk technical indicators. According to VirusTotal, only 2 out of 95 security vendors flagged bsquared.sbs as malicious as of the latest scan—indicating low early detection but high potential harm. The domain was registered through Dynadot LLC and has a recent creation date (March 31, 2026), which is suspicious given the lack of established reputation. While Google Safe Browsing (GSB) status is not specified, the low VT detection suggests it may not yet be widely blacklisted, increasing exposure to unsuspecting users. These factors point to a newly deployed, evolving threat designed to bypass initial security layers.
As of now, bsquared.sbs remains active with an elevated risk level, indicating ongoing malicious operations. PhishDestroy and participating threat intelligence networks continue to monitor and block this domain. Users are strongly advised not to interact with bsquared.sbs or any linked crypto transaction prompts. Due to the sophisticated nature of crypto drainers—often including fake wallet signatures or transaction approvals—the risk of irreversible financial loss is significant. Immediate network-level blocking is recommended for organizations, and personal users should verify URLs via trusted scanners before any interaction.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ZONA SHORTDOT · PROVE PUBBLICHE
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.