near-bonus[.]com
“NEAR | Blockchains, Abstracted”
near-bonus.com — Контент недоступний (HTTP 502). Уособлення бренду: Across; Тип шахрайства: Wallet/seed Phishing. Зведення доказів: VirusTotal 14/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); PhishDestroy score 92/100. Реєстратор: NameSilo.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain near-bonus.com was registered on February 21, 2026 through NameSilo, LLC and is currently listed as offline. DNS resolution points to the IP address 188.114.96.3, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The authoritative nameservers are aitana.ns.cloudflare.com and hans.ns.cloudflare.com, confirming that the domain is hosted behind Cloudflare’s infrastructure. No TLS certificate was observed for the site, indicating that any HTTP service would have been delivered without encryption.
The only visible page metadata is the title "NEAR | Blockchains, Abstracted," which does not directly reference the targeted brand but aligns with the reported scam type of wallet or seed phishing. The domain is associated with a brand impersonation of "across," though the page content has not been publicly examined to verify the exact presentation. Security telemetry shows that 14 of 93 VirusTotal scanners flagged the domain as malicious, and a Gridinsoft trust score of 0 / 100 further reinforces its classification as high‑risk. The domain appears on three independent blocklists and has been proactively blocked by PhishDestroy, MetaMask, and SEAL, suggesting that multiple security products have identified it as part of a credential‑theft infrastructure targeting cryptocurrency wallets.
While the offline status limits immediate observation, defenders should continue to monitor the IP address 188.114.96.3 for related activity, enforce blocklisting of the domain in web filters, and consider adding the associated IP range to threat‑intel feeds. Given the lack of an SSL certificate and the presence of a generic blockchain‑related page title, the site likely served a phishing landing page designed to harvest wallet seeds or private keys. Organizations handling cryptocurrency assets should educate users about unsolicited requests for seed phrases and ensure that any interaction with near-bonus.com is blocked at the network perimeter.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога