bitget-token[.]site
Проверка домена bitget-token.site на фишинг и безопасность
“BITGET-TOKEN”
bitget-token.site — Контент недоступен (HTTP 502). Олицетворение бренда: Bitget; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 10/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); Google Safe Browsing flagged; PhishDestroy score 80/100. Регистратор: NameSilo.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
bitget-token.site was registered with NameSilo, LLC on 13 September 2025 and is currently reported as offline. The domain resolves to the IPv4 address 43.212.99.130, which is announced by AS16509 belonging to Amazon.com, Inc. and geolocated to Taiwan. The hosting provider is therefore a cloud service operated by Amazon Web Services. No TLS certificate is presented for the host, indicating the site was served over plain HTTP. The page title returned by the site, “BITGET‑TOKEN”, aligns with the declared brand impersonation of Bitget, and the intelligence tags the activity as a crypto‑scam.
Google Safe Browsing classifies the URL as a social‑engineering threat, and PhishDestroy has listed the domain on its blocklist. VirusTotal scans show that 10 of 95 scanned security vendors flagged the domain as malicious. Additional reputation data includes a Gridinsoft trust score of 0 out of 100 and a single entry on a security blocklist. AlienVault OTX reports the domain in one threat‑intelligence pulse.
The domain is serviced by the Cloudflare name servers dylan.ns.cloudflare.com and zoe.ns.cloudflare.com. Given the combination of registrar information, cloud hosting, lack of encryption, multiple vendor detections, safe‑browsing warning, and low trust score, the evidence strongly supports a high‑risk classification. Defenders should continue to block the domain and its associated IP address at perimeter filters, add the observed name servers to monitoring lists, and ensure that any traffic to bitget-token.site is denied or logged for further investigation. Ongoing threat‑intel feeds should be consulted for any reappearance, and incident response teams should be alerted if users report unsolicited communications referencing the domain.
Сигналы безопасности
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание