bulltheleader[.]top
bulltheleader.top — Прикритий · доступний. Зведення доказів: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. Реєстратор: 耐思尼克国际集团有限公司.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of bulltheleader.top indicates an active phishing domain registered on April 17, 2026, through a registrar identified as 耐思尼克国际集团有限公司. The domain currently resolves to IP address 104.21.10.48, which is part of Cloudflare's infrastructure in Canada. Infrastructure analysis reveals Cloudflare nameservers (june.ns.cloudflare.com and nikon.ns.cloudflare.com) and a Let's Encrypt SSL certificate (serial E7), suggesting the use of automated provisioning common in both legitimate and malicious deployments. The domain returns an HTTP 403 status with the page title 'Just a moment...', a response pattern often associated with Cloudflare's interstitial pages or newly configured phishing kits awaiting activation. While the exact content or target of the phishing campaign remains unconfirmed, the domain appears on three security blocklists and was included in one AlienVault OTX threat intelligence pulse, indicating prior detection by automated systems. Two of 94 security vendors on VirusTotal flagged the domain at the time of assessment. Defenders should treat this domain as high-risk due to its recent registration, Cloudflare hosting, and presence on multiple blocklists. Network-level blocking is recommended pending further content analysis, particularly for organizations that may be targeted by credential harvesting or financial fraud campaigns. The domain's continued activity as of July 12, 2026, suggests it may still be in use or awaiting deployment in ongoing phishing operations.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога