MALICIOUS — CRITICAL
letlsbonk[.]fun
This domain is flagged for elevated-risk brand impersonation targeting Gemini, a cryptocurrency exchange platform.
- VirusTotal
- 4/95
- Blocklists
- No stored match
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
letlsbonk.fun — Контент недоступен (HTTP 502). Олицетворение бренда: Gemini; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 4/95 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 100 det.; PhishDestroy score 95/100. Регистратор: PDR.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
This domain is flagged for elevated-risk brand impersonation targeting Gemini, a cryptocurrency exchange platform. Analysis indicates the site was designed to deceive users into disclosing login credentials, wallet keys, or personal information by mimicking Gemini’s branding and interface elements. The threat type falls under credential harvesting through brand spoofing, a common tactic in cryptocurrency-related phishing campaigns. Infrastructure analysis reveals the domain letlsbonk.fun was registered on August 06, 2025, through PDR Ltd. d/b/a PublicDomainRegistry.com. It resolves to the IP address 104.21.48.1 and has been detected by 4 out of 95 security vendors on VirusTotal. The domain appears on one security blocklist and holds a Gridinsoft trust score of 0/100. The page title, Bonk.fun, further suggests an attempt to mislead users familiar with cryptocurrency-related services. Current status confirms the domain has been taken offline, though historical activity remains a concern for retrospective threat analysis. Mitigation steps for this threat type include immediate blacklisting of the domain and associated IP address within enterprise security systems. Organizations should monitor for any residual DNS queries or cached references to letlsbonk.fun in network logs. Users who may have interacted with the domain should be advised to rotate credentials, enable multi-factor authentication, and verify wallet security settings. Cryptocurrency exchanges and financial platforms should proactively warn users about brand impersonation risks and provide guidance on identifying spoofed domains through official communication channels.
Охват данных12 recorded checks
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.