btcbultolkens[.]com
“Account Suspended”
btcbultolkens.com — Непроверенный. Тип мошенничества: Account Takeover. Сводка доказательств: VirusTotal 2/95 (Gridinsoft, Seclookup); Spamhaus DBL_PHISH; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 78/100. Регистратор: GoDaddy.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain btcbultolkens.com was registered on July 06, 2025 through GoDaddy.com, LLC and currently resolves to the IPv4 address 198.12.66.123, which belongs to AS36352 HostPapa and is geolocated in the United States. The site presents a TLS certificate issued by GoDaddy TLS Intermediate CA DV, confirming that the certificate chain is valid and that the domain is using a standard SSL provider. An HTTP request to the host returns a 200 status code and the page title is "Account Suspended," indicating that the content displayed is a generic suspension notice rather than a functional service.
The domain is listed on four external security blocklists and has been actively blocked by multiple anti‑phishing services, including PhishDestroy, Polkadot, Enkrypt, and Codeesura. VirusTotal analysis shows that two of ninety‑five security vendors have flagged the domain, providing additional corroboration of malicious intent. The threat classification associated with the domain is "Account Takeover," suggesting that attackers may be attempting to harvest credentials or hijack user accounts, although the exact target brand or service is not disclosed in the available data.
Defenders should treat the domain as high‑risk: ingest the domain into DNS sinkhole or blocklist configurations, enforce outbound traffic filtering for the resolved IP, and monitor TLS handshake logs for connections to the GoDaddy‑issued certificate. Alerting on any user‑initiated connections to the host, especially from internal workstations, will help contain potential credential‑theft attempts. Continuous re‑evaluation is advised, as the current evidence is limited to registration details, hosting infrastructure, and blocklist presence; further investigation of request patterns and any associated payloads would clarify the full scope of the campaign.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Анализ конфигурации сайта
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание