MALICIOUS — CRITICAL
Проверка домена binanceguidance.com на фишинг и безопасность
binanceguidance[.]
binanceguidance.com is a newly registered domain (created 21 Feb 2026) that was observed hosting a page titled “Binance Verify Official”.
- VirusTotal
- 14/93
- Blocklists
- No stored match
- Доступность
- Непроверенный
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
binanceguidance.com — Непроверенный. Олицетворение бренда: Binance; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 14/93 (ADMINUSLabs, alphaMountain.ai, Certego, CRDF, CyRadar); PhishDestroy score 92/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
binanceguidance.com is a newly registered domain (created 21 Feb 2026) that was observed hosting a page titled “Binance Verify Official”. The site was hosted behind Cloudflare’s DNS service using the nameservers gabe.ns.cloudflare.com and tara.ns.cloudflare.com, and did not present an SSL/TLS certificate, causing HTTP connections to be unencrypted. Network resolution points to the IPv4 address 3.1.139.30, which belongs to Amazon.com, Inc. (AS16509) and is geolocated to Singapore. The domain is explicitly crafted to impersonate the cryptocurrency exchange Binance, as indicated by the brand target and the page title.
VirusTotal analysis shows that 14 of 93 scanned security vendors flagged the domain as malicious, reflecting a moderate consensus of detection. The domain appears in a single threat‑intelligence pulse on AlienVault OTX and is listed on one public security blocklist. PhishDestroy has taken the site offline and confirmed the takedown.
Current status is “offline”, but the infrastructure footprint remains observable. Defenders should add 3.1.139.30 and the domain name to deny‑list rules, monitor for any residual DNS queries, and ensure that any internal email or web filters reference the latest blocklist entries. Continuous re‑scanning is recommended to capture possible re‑hosting attempts, and any endpoints that have previously accessed the URL should be inspected for credential leakage related to the Binance brand.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.