MALICIOUS — CRITICAL
bookkooks[.]com
This domain, bookkooks.com, has been confirmed as a credential theft phishing site designed to harvest user login credentials through deceptive login portals.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Доступність
- Останній відомий активний · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@trustname.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
bookkooks.com — Останній відомий активний (HTTP 200). Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 71/100. Реєстратор: Fewmoretaps OU d/b/a T….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
This domain, bookkooks.com, has been confirmed as a credential theft phishing site designed to harvest user login credentials through deceptive login portals. Analysis indicates no direct association with a specific brand or cryptocurrency drainer kit, but the infrastructure and detected technologies suggest a broad targeting approach typical of credential harvesting campaigns. The site employs social engineering tactics to trick users into submitting sensitive information, which is then exfiltrated to attacker-controlled servers. Infrastructure analysis reveals the following technical indicators: the domain was registered on April 28, 2026, through Fewmoretaps OU d/b/a Trustname.com. It resolves to the IP address 208.109.20.54 and is currently associated with a Let's Encrypt SSL certificate. The domain appears on one security blocklist and is flagged by 3 out of 95 security vendors on VirusTotal. Detected technologies include WordPress, MySQL, PHP, Apache HTTP Server, jQuery Migrate, jQuery, Google Tag Manager, and Google Analytics, which are commonly exploited to facilitate phishing operations. As of the latest assessment, bookkooks.com has been taken offline, reducing immediate exposure risk. However, the domain remains registered and could be reactivated or repurposed for future malicious activity. The registrar and hosting provider have not publicly disclosed remediation actions, leaving residual risk for users who may have interacted with the site prior to its takedown. Organizations are advised to block the domain and associated IP at the network level, monitor for indicators of compromise, and educate users on recognizing credential theft attempts. The elevated risk level justifies continued vigilance, particularly for entities whose users may have been exposed to the phishing campaign.
Обсяг даних13 recorded checks
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 9 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org 100% впевненостіApache is a free and open-source cross-platform web server software.
httpd.apache.org 100% впевненостіQuery Migrate is a javascript library that allows you to preserve the compatibility of your jQuery code developed for versions of jQuery older than 1.9.
github.com 100% впевненостіjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% впевненостіGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 100% впевненостіGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% впевненостіDataTables is a plug-in for the jQuery Javascript library adding advanced features like pagination, instant search, themes, and more to any HTML table.
datatables.net 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of bookkooks.com · checked Jun 26, 2026
Аналіз конфігурації сайту
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260428-868DB2 Recipient: abuse@trustname.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.