MALICIOUS — CRITICAL
buepux[.]com
PhishDestroy identifies buepux.com as an active cryptocurrency wallet drainer phishing domain targeting unsuspecting users through fraudulent schemes.
- VirusTotal
- 2 detections
- Blocklists
- 3 · MetaMask, ScamSniffer
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
buepux.com — Контент недоступний (HTTP 502). Уособлення бренду: Cryptoscam; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 2 detections (engine total unavailable) (alphaMountain.ai, Gridinsoft); URLQuery 2 alerts; URLScan malicious verdict; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 79/100. Реєстратор: PDR.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
PhishDestroy identifies buepux.com as an active cryptocurrency wallet drainer phishing domain targeting unsuspecting users through fraudulent schemes. The domain masquerades as a legitimate service to deceive victims into connecting their wallets, where malicious scripts then drain cryptocurrency assets. No specific brand or drainer kit was identified in the available intelligence, but the domain’s behavior aligns with common wallet drainer tactics observed in recent campaigns.
This domain was flagged with a VirusTotal detection score of 2 out of 95 security vendors, indicating limited but concerning recognition within the security community. It is registered through PDR Ltd. d/b/a PublicDomainRegistry.com and resolves to IP address 188.114.97.3. The domain was created on May 03, 2026, and currently appears on 2 security blocklists, including blocks enforced by MetaMask and SEAL. Additionally, the domain utilizes a Let’s Encrypt SSL certificate, which may lend it an air of legitimacy to unsuspecting users.
As of the latest analysis, buepux.com remains active and poses an elevated risk to potential victims. Blocked by major security solutions like MetaMask and SEAL, the domain’s activity is partially mitigated, but users should remain cautious. The remaining risk is elevated due to the domain’s recent creation, low blocklist coverage, and the potential for further evasion tactics. Users are advised to avoid interacting with this domain and verify website legitimacy through trusted sources before engaging in any cryptocurrency-related transactions.
Обсяг даних14 recorded checks
Сигнали безпеки
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | buepux.com |
malicious | Sinkholed |
| DNS4EU | buepux.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260508-6FC289 Recipient: sfoster22@ycyfugihih.cfd Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.