huitianbusiness[.]com
“汇天交易所”
huitianbusiness.com — Контент недоступний. Уособлення бренду: Binance. Зведення доказів: VirusTotal 0/93; URLQuery 3 det.; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: Hello Internet.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of huitianbusiness.com shows a newly registered domain (created 27 February 2026) that resolves to the Cloudflare address 188.114.96.3, hosted in the United States under ASN 13335. The domain is delegated to Cloudflare nameservers amanda.ns.cloudflare.com and milan.ns.cloudflare.com, and it does not present an SSL/TLS certificate, indicating that any web service would be delivered over plain HTTP. The site title returned from the host is "汇天交易所", suggesting an attempt to impersonate a Chinese‑language exchange service.
The domain has been taken offline at the time of assessment, but it is listed on three public security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL. No detection vendors have flagged the domain, and the absence of detections does not imply safety. The registrar listed is Hello Internet Corp, a legitimate registration service that does not provide immediate mitigation.
Given the short lifespan, lack of encryption, and presence on multiple blocklists, the infrastructure points to a typical phishing deployment rather than a legitimate business. Defenders should continue to block the domain and the associated IP address, monitor for any re‑registration or use of the same IP range, and consider adding the host to internal URL filtering and DNS sinkhole rules. Further investigation of the page content, if restored, would be required to confirm the exact phishing vector and any credential‑stealing mechanisms.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260227-93ED72 Recipient: abuse@hello.co Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога