wallet.billons.network
“Billions | Wallet”
wallet.billons.network identified as credential phishing targeting Apple users. Domain flagged by 13/95 security engines, currently offline but previously.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
증거 요약
The domain wallet.billons.network has been confirmed as a credential phishing site specifically targeting Apple users through brand impersonation. Analysis indicates the site masqueraded as an Apple Wallet service, aiming to harvest user credentials and sensitive financial information. As of the latest verification, the domain has been taken offline, though it remains a documented threat in security databases. Infrastructure analysis reveals the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolved to the IP address 172.67.156.69. The site was flagged by 13 of 95 security vendors on VirusTotal, indicating a high level of detection consensus. It appears on two security blocklists, including PhishDestroy and ScamSniffer, and was secured with a Let's Encrypt SSL certificate, a common tactic to lend superficial legitimacy. The page title, 'Billions | Wallet,' further suggests an attempt to mimic legitimate digital wallet services. Current status confirms the domain is offline, reducing immediate risk to end users. However, the infrastructure and registration patterns remain relevant for threat intelligence. Organizations are advised to block the domain and associated IP at the network level, update endpoint protection signatures, and monitor for any re-emergence under similar naming conventions. Users who may have interacted with the site should reset credentials for Apple services and enable multi-factor authentication where available. Security teams should review logs for connections to 172.67.156.69 and the domain to identify potential compromise indicators.
네트워크 보안 인텔리전스 Registrar context
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jun 26, 2026 · 16:20 UTCVirusTotal scanner detections updated from 8 to 13. Added scanner alerts: BitDefender, CRDF, Lionic, VIPRE, alphaMountain.ai.
위협 대응 Pipeline
공개 차단 목록 상태
탐지 회피 분석
클로킹 의심: 스캐너와 방문자 제목이 다름
관찰되지 않음
저장된 스캔 결과에서는 클로킹 현상이 관찰되지 않았습니다.
이 호스트에 대해 저장된 크롤러 대 브라우저 관측 데이터와, 케이타로 스타일의 트래픽 분배 시스템을 위한 실시간 지문 확인 정보.
- 저장된 은신 플래그
- 관찰되지 않음
- 클로킹 점수
- 0/6
- 마지막 은폐 스캔
- 스캐너가 감지한 서버 헤더
cloudflare
스캐너 메모: redirect: raw=redirect_301; http=301; via=http_proxy; location=https://wallet.billons.network/; server=cloudflare
저장된 캡처 · 2 sources
도메인 인텔리전스
기술 세부 정보DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
Registration: billons.network
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For the registrable domain billons.network behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-24 02:45:07 UTC
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of wallet.billons.network · checked Jun 26, 2026
커뮤니티 신고
커뮤니티 구성원 1명이 신고 · 최초 확인 2026년 3월 17일
- 저장된 신고
- 1
- 신고된 고유 URL
- 1
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.