bluko[.]top
Перевірка домену bluko.top на фішинг і безпеку
“VAN”
bluko.top — Контент недоступний (HTTP 502). Уособлення бренду: Phantom; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 3/95 (G-Data, Gridinsoft, SOCRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100. Реєстратор: NameSilo.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain bluko.top is a phishing site engaged in brand impersonation targeting users of the Phantom cryptocurrency wallet. It was designed to deceive victims into believing they were interacting with the legitimate Phantom platform, potentially leading to credential theft or unauthorized transactions. As of the latest verification, bluko.top has been taken offline, though its prior activity remains a confirmed scam.
Technical analysis of bluko.top reveals limited but notable detection: 3 of 95 security vendors on VirusTotal flagged the domain, including G-Data, Gridinsoft, and SOCRadar, while Gridinsoft assigned it a trust score of 0/100. The domain was registered on August 19, 2025, through NameSilo, LLC, and resolved to the IP address 45.67.85.152, hosted by Kuroit Limited (AS203363) in the United Kingdom. It appeared on two security blocklists, PhishDestroy and ScamSniffer, and used nameservers ns1.dnsowl.com, ns2.dnsowl.com, and ns3.dnsowl.com. No SSL certificate was present, and the observed page title was 'VAN'.
Users who interacted with bluko.top should immediately revoke any token approvals granted to unknown contracts and transfer funds to a new, secure wallet. Enable two-factor authentication (2FA) on all cryptocurrency accounts and monitor for unauthorized transactions. Change passwords for any accounts accessed while the site was active. Report the domain to relevant platforms, including Phantom’s official support channels, and submit it to additional blocklists such as Google Safe Browsing or PhishTank to prevent further abuse.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога