bkwithpioneer[.]icu
bkwithpioneer.icu — Неперевірений. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 7/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; PhishDestroy score 83/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
bkwithpioneer.icu was registered on 23 April 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. The zone is hosted on Cloudflare with authoritative name servers lamar.ns.cloudflare.com and sima.ns.cloudflare.com and resolves to the IPv4 address 188.114.97.3, which is geolocated to Canada and associated with Cloudflare, Inc. The site presents an HTTP 403 response and a page title “Just a moment…”, indicating a potential interstitial check but no further content has been captured. The TLS certificate is issued by Let’s Encrypt (identifier YE1) and is currently valid. Reputation data shows a Gridinsoft trust score of 0/100, and the domain appears on one public blocklist and has been blocked by PhishDestroy. Threat intelligence sources list the domain in a single AlienVault OTX pulse and VirusTotal records indicate that six of ninety‑four scanning engines have flagged the host as malicious. The classification provided is generic credential phishing, though the specific victim brand or login portal being spoofed has not been observed. Infrastructure analysis confirms the use of a shared Cloudflare front‑end, a common tactic for fast‑deployment phishing sites, and the recent registration date suggests a short‑lived campaign. Uncertainty remains regarding the exact phishing landing page, payload, and any credential harvesting mechanisms, as no page content beyond the title has been disclosed. Defenders should add bkwithpioneer.icu to blocklists, monitor DNS queries for the domain and its associated IP, and enforce TLS inspection to capture any subsequent HTTP traffic. Given the active status and existing detections, early blocking is recommended to prevent potential credential compromise.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ЗОНА SHORTDOT · ПУБЛІЧНІ ДОКАЗИ
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-18 02:38:51 UTC
Аналіз VirusTotal
Аналіз конфігурації сайту
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога