MALICIOUS — CRITICAL
bountyaistake[.]com
14 of 93 security engines flagged the domain; the latest stored check returned HTTP 502.
- VirusTotal
- 14/93
- Blocklists
- No stored match
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bountyaistake.com — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: MetaMask; Dolandırıcılık türü: Wallet/seed Phishing. Kanıt özeti: VirusTotal 14/93 (alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, CRDF, CyRadar); URLQuery 1 alert; Google Safe Browsing flagged; PhishDestroy score 95/100. Kayıt kuruluşu: PDR.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Digest
bountyaistake.com is classified critical with an evidence score of 95/100. 14 of 93 security engines flagged the domain. Registration metadata recorded via PDR Ltd. d/b/a PublicDomainRegistry.com, hosted on 172.67.218.16 (CLOUDFLARENET - Cloudflare, Inc., US, US). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 24 Jan 2026.
Stored generated summary (templated)mistral · 23.07.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, bountyaistake.com, was registered on February 21, 2026, and is assessed as a high-risk seed-phishing operation targeting Metamask users. Analysis indicates the site resolved to 172.67.218.16 (AS13335 Cloudflare, US) and used Cloudflare nameservers sneh.ns.cloudflare.com and tony.ns.cloudflare.com. The page title, $BOUNTY | Highest USDT Rewards, suggests a cryptocurrency reward scam, aligning with the wallet/seed phishing classification in available intelligence. Google Safe Browsing flagged the domain for social engineering, and it appeared on one security blocklist (PhishDestroy).
Gridinsoft assigned a trust score of 0/100. VirusTotal detections from 14 of 93 security vendors further support the malicious classification. The domain was hosted behind Cloudflare, using HTTP/3 and a Google Trust Services SSL certificate (WE1).
As of July 23, 2026, the domain is offline, though defenders should treat any reactivation as a critical threat. No evidence links this domain to a known phishing kit or additional infrastructure. Defenders are advised to block the domain, IP, and associated SSL certificate in perimeter controls, monitor for related domains using the same registrar (PDR Ltd. d/b/a PublicDomainRegistry.com), and alert users to the seed-phishing risk targeting cryptocurrency wallets.
Veri kapsamı13 recorded checks
Güvenlik Sinyalleri
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | bountyaistake.com/main.bbc2594c9c69111e.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
Teknolojiler · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
PD-20260124-E58DE9 Recipient: abuse-contact@publicdomainregistry.com Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.