MALICIOUS — CRITICAL
bonusweb.org için kimlik avı ve güvenlik kontrolü
bonusweb[.]
PhishDestroy identifies bonusweb.org as a generic phishing domain impersonating rewards and giveaway platforms to harvest login credentials and personal data.
- VirusTotal
- 9/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bonusweb.org — Bilinen son aktif (HTTP 301). Dolandırıcılık türü: Fake Airdrop. Kanıt özeti: VirusTotal 9/91 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, CyRadar, Fortinet); URLQuery 2 alerts; PhishDestroy score 87/100. Kayıt kuruluşu: PDR.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
PhishDestroy identifies bonusweb.org as a generic phishing domain impersonating rewards and giveaway platforms to harvest login credentials and personal data. The domain exhibits typical phishing characteristics, including recent registration and low detection rates, suggesting an active threat campaign targeting unsuspecting users. No specific drainer kit or brand impersonation has been conclusively linked to this domain at the time of this report, but the structure aligns with common credential harvesting schemes.
This domain was flagged with a VirusTotal detection score of 9/95, indicating no current detections among major security vendors. It was registered through PDR Ltd. d/b/a PublicDomainRegistry.com, resolves to IP address 178.253.46.86, and utilizes a Let's Encrypt SSL certificate for legitimacy. The domain was created on June 01, 2023, and remains unblocked by Google Safe Browsing (GSB) at this time. The low detection rate and active status warrant immediate caution, as it may evade traditional security measures.
As of the latest analysis, bonusweb.org remains classified as 'active' with a risk level of 'under_investigation'. Users are advised to avoid interacting with this domain and report it to their security teams or relevant phishing databases. The current risk is elevated due to the lack of vendor detections and the domain's recent activity. PhishDestroy continues to monitor this domain, and security researchers are encouraged to submit additional threat intelligence to refine classification and mitigation strategies. Remaining risk includes potential data theft or malware distribution if users engage with the site.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı13 recorded checks
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | bonusweb.org |
malicious | Sinkholed |
| Hagezi Threat Feed | bonusweb.org |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.