bsquared[.]sbs
bsquared.sbs 피싱 및 보안 점검
“bsquared.sbs | 504: Gateway time-out”
bsquared.sbs — 콘텐츠를 사용할 수 없음 (HTTP 404). 사기 유형: Crypto Drainer. 증거 요약: VirusTotal 4/91 (Bfore.Ai PreCrime, Gridinsoft, SOCRadar, Webroot); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. 등록기관: Dynadot.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Evidence Analysis
PhishDestroy identifies bsquared.sbs (registered March 31, 2026) as an active crypto drainer phishing domain designed to steal cryptocurrency assets by impersonating legitimate crypto services or platforms. The domain operates a fake login portal or transaction interface that silently drains wallets upon user interaction, typical of modern drainer kits leveraging social engineering and blockchain interaction prompts. The infrastructure includes a Let's Encrypt SSL certificate, suggesting an attempt to appear legitimate, and is hosted behind Cloudflare at IP 172.67.177.221, a common tactic to obscure origin and evade takedown efforts.
This domain exhibits multiple high-risk technical indicators. According to VirusTotal, only 2 out of 95 security vendors flagged bsquared.sbs as malicious as of the latest scan—indicating low early detection but high potential harm. The domain was registered through Dynadot LLC and has a recent creation date (March 31, 2026), which is suspicious given the lack of established reputation. While Google Safe Browsing (GSB) status is not specified, the low VT detection suggests it may not yet be widely blacklisted, increasing exposure to unsuspecting users. These factors point to a newly deployed, evolving threat designed to bypass initial security layers.
As of now, bsquared.sbs remains active with an elevated risk level, indicating ongoing malicious operations. PhishDestroy and participating threat intelligence networks continue to monitor and block this domain. Users are strongly advised not to interact with bsquared.sbs or any linked crypto transaction prompts. Due to the sophisticated nature of crypto drainers—often including fake wallet signatures or transaction approvals—the risk of irreversible financial loss is significant. Immediate network-level blocking is recommended for organizations, and personal users should verify URLs via trusted scanners before any interaction.
데이터 적용 범위12 recorded checks
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
SHORTDOT 영역 · 공개 증거
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
사용 기술 · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 신뢰도 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 신뢰도 100%VirusTotal 분석
증거 및 외부 보고서Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.