bitget[.]dad
“在Bitget注册以获得最高6,200 USDT的奖金 | Bitget”
bitget.dad — Непроверенный. Олицетворение бренда: Apple; Тип мошенничества: Tech Support Scam. Сводка доказательств: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Forcepoint ThreatSeeker, Gridinsoft); PhishDestroy score 65/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
bitget.dad is an active domain that masquerades as Apple in a brand‑impersonation campaign. The site presents a Chinese page title “在Bitget注册以获得最高6,200 USDT的奖金 | Bitget”, indicating a promotional message unrelated to Apple, yet the underlying intent is to lure victims by referencing Apple services such as Apple Sign‑in. The campaign is classified as a tech‑support scam and carries a high risk rating. Infrastructure analysis shows the domain is registered through Cloudflare, Inc. and resolves to the IPv4 address 8.223.30.170. The address is assigned to an Alibaba (US) Technology Co., Ltd. ASN (AS45102) and geolocates to Hong Kong. DNS resolution uses the Cloudflare authoritative nameservers carioca.ns.cloudflare.com and felicity.ns.cloudflare.com. The TLS certificate is issued by Google Trust Services under the WE1 root, providing HTTPS with HSTS enabled. Technical fingerprinting reveals a Node.js stack running Express, with front‑end components built on Vue.js, Nuxt.js, and Apple Sign‑in integration. The backend is hosted on Amazon Web Services, and traffic is tracked by Naver Analytics. Security scanners flag the domain on a single blocklist and assign a Gridinsoft trust score of 0 / 100. VirusTotal reports that 1 of 95 security vendors has flagged the domain, and PhishDestroy has already blocked it. The HTTP response is a 301 redirect, and the site remains reachable. Defenders should add 8.223.30.170 and the domain bitget.dad to network‑level deny lists, enforce DNS sinkholing for the associated Cloudflare nameservers, and monitor for any use of the Apple Sign‑in endpoint originating from this infrastructure. Continuous re‑evaluation is advised, as the low trust score and active blocklist status suggest the operator may shift hosting or modify the payload. Incident response teams should treat any credential or support‑request traffic associated with this domain as malicious.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 10 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Progressive JavaScript framework for building user interfaces.
Hybrid Vue framework for server-side rendering and static sites.
Cloud computing platform offering compute, storage, and networking services.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comАнализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of bitget.dad · checked Mar 2, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание