bbwukjih[.]dnq[.]r[.]110880[.]cn
“TikTok”
bbwukjih.dnq.r.110880.cn — Conteúdo indisponível. Representação da marca: TikTok; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 17/93 (Criminal IP, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 95/100. Registrador: Dynadot.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis indicates that the domain bbwukjih.dnq.r.110880.cn was registered on August 2, 2025 through Dynadot LLC and is currently taken offline. The domain resolves to the IPv4 address 38.46.13.34, which is announced by AS9294 GNET INC. and geolocated to Hong Kong. No TLS certificate is presented, meaning the site would have been served over plain HTTP only. The page title returned from the host is “TikTok”, matching the declared brand target of TikTok and confirming a brand‑impersonation motive.
Google Safe Browsing has flagged the domain for social engineering, and Gridinsoft assigns a trust score of 0 out of 100, indicating a high likelihood of malicious intent. VirusTotal reports that 17 out of 93 scanning engines have identified the domain as malicious, reinforcing the suspicion. The domain is listed on a single security blocklist and has been actively blocked by PhishDestroy. Nameserver records point to ns1.dnsip.com and ns2.dnsip.com, which are commonly used by disposable or fast‑flux services.
The combination of a recent registration, lack of encryption, low trust score, multiple vendor detections, and explicit brand targeting provides concrete evidence that the domain was employed for brand‑impersonation attacks against TikTok users. Uncertainty remains regarding the exact payload or credential‑harvesting mechanisms because the site content has not been captured; however, the existing indicators are sufficient for defensive actions. Organizations should add the domain to internal blocklists, monitor DNS queries for the associated IP and nameservers, and ensure that web filtering solutions incorporate the Google Safe Browsing and PhishDestroy classifications. Continuous re‑scanning of the IP address is advised in case the domain becomes active again.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo