Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@kouming.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
h5[.]higico[.]top
“BitGet”
h5.higico.top — Non verificato. Simulazione del marchio: Bitget; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 14/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 2 alerts; PhishDestroy score 95/100. Registrar: Hongkong Kouming Inter….
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy identifies h5.higico.top as an active brand impersonation page targeting Bitget users. This domain was flagged by 10 of 95 VirusTotal security vendors, confirming malicious intent. Registered through Hongkong Kouming International Limited on February 11, 2026, the site resolves to IP 223.26.62.92 and employs a Let's Encrypt SSL certificate to appear legitimate. Its page title matches Bitget’s branding, creating a deceptive user experience designed to harvest login credentials or financial details.
This domain’s high-risk status reflects its recent creation, low detection rate, and direct impersonation of a major cryptocurrency exchange. At just days old, h5.higico.top evades broader blocklists due to minimal flagging, allowing it to operate undetected. The precise threat is credential theft via a spoofed Bitget login portal, where user inputs are siphoned to attacker-controlled infrastructure. Technical indicators include the use of a valid SSL certificate to bypass browser warnings, a domain name designed to resemble Bitget’s official subdomains, and targeting of users through phishing emails or fake ads. The combination of recent registration, specific impersonation, and partial detection suggests an emerging campaign actively seeking victims.
If you visited h5.higico.top or entered credentials, immediately change your Bitget password from a known-safe device and enable two-factor authentication. Scan your device for malware using a reputable antivirus tool, as this site may have deployed infostealers. Report the domain to Bitget’s security team via their official channels and your local cybercrime unit. Avoid clicking links from unsolicited messages; always verify URLs by typing them manually or using bookmarks. Block the IP 223.26.62.92 and domain h5.higico.top via your firewall or network settings to prevent further exposure. Exercise heightened caution with all cryptocurrency-related communications, as threat actors frequently exploit brand trust in this sector.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Registration: higico.top
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain higico.top behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 3 identified
Progressive JavaScript framework for building user interfaces.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of h5.higico.top · checked Apr 15, 2026
Dati e relazioni esterne
PD-20260415-9B7298 Recipient: abuse@kouming.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo