bsckpack[.]exchange
“Home - Backpack: Crypto Exchange & Wallet | Solana, Ethereum & BTC”
bsckpack.exchange — Последний известный активный (HTTP 301). Олицетворение бренда: Aave; Тип мошенничества: Fake Exchange. Сводка доказательств: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); Spamhaus DBL_PHISH; PhishDestroy score 96/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis conducted on July 22, 2026 identifies bsckpack.exchange as an active brand‑impersonation infrastructure targeting the Aave community. The domain was registered on February 21, 2026 through NiceNIC International Group Co., Limited and is hosted behind Cloudflare (ASN 13335). DNS resolution points to IP 172.67.179.206, which GeoIP attributes to the United States. The authoritative nameservers are alexa.ns.cloudflare.com and nolan.ns.cloudflare.com, confirming the use of Cloudflare’s DNS service. HTTP inspection returns a 301 redirect, and the TLS certificate is issued by Google Trust Services under the WE1 intermediate, indicating a valid‑looking HTTPS endpoint.
The front‑end stack reports React, HSTS enforcement, Cloudflare Browser Insights and HTTP/3, consistent with a modern web application that could host a counterfeit crypto exchange interface. The page title presented by the server is “Home - Backpack: Crypto Exchange & Wallet | Solana, Ethereum & BTC”, which aligns with the declared scam type “Fake Exchange”. Reputation checks show the domain appears on one security blocklist and is explicitly listed by PhishDestroy. Automated scoring from Gridinsoft assigns a trust score of 0 / 100, reflecting extreme suspicion. VirusTotal analysis registers detections from 2 of 93 scanning engines, confirming that at least two independent vendors consider the site malicious.
No additional intelligence such as OTX tags or Safe Browsing entries is currently available. The evidence collectively points to a high‑risk impersonation campaign that likely harvests credentials or funds from users seeking to trade Aave‑related assets. Uncertainty remains regarding the specific phishing page content and any associated command‑and‑control infrastructure, as no visual inspection has been performed. Defenders should immediately block DNS resolution for bsckpack.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-23 02:40:05 UTC
Технологии · 5 identified
React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Анализ конфигурации сайта
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание