bonus-methprotocol[.]com
“bonus-methprotocol.com | 504: Gateway time-out”
Resumo das evidências
Analysis of bonus-methprotocol.com shows a newly registered domain (created 1 December 2025) that is currently taken offline and returns HTTP 404 with a page title “504: Gateway time‑out”. The domain resolves to 188.114.97.3, an address owned by AS13335 Cloudflare, Inc. in the United States. DNS is served by alexa.ns.cloudflare.com and randall.ns.cloudflare.com, confirming Cloudflare as the hosting provider and indicating the use of HTTP/3. The TLS certificate is issued by Google Trust Services under the WE1 intermediate, showing a valid HTTPS endpoint despite the site being unavailable. Threat intelligence flags the domain as a “Fake Airdrop” scam.
It appears on one public security blocklist and is listed in an AlienVault OTX pulse, demonstrating that at least one community source has correlated it with malicious activity. PhishDestroy has also blocked the domain, and VirusTotal records seven detections out of ninety‑five scanners, providing additional corroboration of its malicious nature. No further content analysis is possible because the site is offline and the HTTP response is a 404/504 combination, so the exact landing page or credential‑capture mechanisms cannot be verified. Defenders should treat bonus-methprotocol.com as a confirmed malicious actor.
Immediate actions include adding the domain and its resolving IP to network‑level deny lists, configuring DNS filtering to block resolution, and updating email security gateways to flag any messages containing the domain. Continuous monitoring of the IP address and Cloudflare nameservers is advised in case the operator reactivates the site or migrates to a different host. Correlating logs for outbound connections to 188.114.97.3 or TLS handshakes with the Google Trust Services certificate can help identify compromised hosts that have already interacted with the site.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Status do domínio
Inacessível → Acessível
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo