platform-bitbuycdn[.]wixstudio[.]com
“Log In™ | Bitbuy®® | Secure Access®®®™”
Зведення доказів
This domain is flagged as an elevated-risk phishing site specifically targeting cryptocurrency users through brand impersonation. Analysis indicates the threat actor created a fraudulent login portal mimicking the Bitbuy exchange, likely intended to harvest credentials for subsequent account compromise or crypto asset theft. The page title, "Log In™ | Bitbuy®® | Secure Access®®®™," exhibits deliberate misuse of trademark symbols to lend false legitimacy, a common tactic in crypto-focused phishing campaigns.
Infrastructure analysis reveals the domain resolved to IP address 34.144.206.118 and was registered through GoDaddy.com, LLC. The site appears on three security blocklists (PhishDestroy, PhishingArmy, OISD) and holds a Gridinsoft trust score of 0/100. VirusTotal reports 5/95 security vendors flagging the domain as malicious. The SSL certificate was issued by Let's Encrypt, and detected technologies include Wix hosting, React framework, Google Cloud infrastructure, Lodash, HSTS, Google Cloud CDN, and HTTP/3. The domain has since been taken offline, though historical DNS records confirm its prior operational status.
Mitigation for this specific threat type involves immediate credential rotation for any users who may have interacted with the fraudulent portal. Organizations should implement domain monitoring to detect similar impersonation attempts, particularly those leveraging cloud hosting providers (e.g., Google Cloud) and content delivery networks. Security teams are advised to block the IP address 34.144.206.118 at perimeter defenses and update phishing detection rules to account for the use of trademark symbols in page titles. Given the crypto-focused nature of this attack, additional scrutiny should be applied to internal cryptocurrency transaction processes and multi-factor authentication enforcement for exchange-related accounts.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Registration: wixstudio.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wixstudio.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 7 технологій із високою впевненістю
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of platform-bitbuycdn.wixstudio.com · checked Jun 25, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога