was[.]becrown[.]life
“becrown.life | 526: Invalid SSL certificate”
was.becrown.life — Неперевірений. Уособлення бренду: Binance; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 78/100. Реєстратор: Global Domain Group.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain was.becrown.life has been identified as a high‑risk brand‑impersonation site targeting users of the Binance platform. The site is actively serving content and returns HTTP status code 526, indicating an invalid SSL certificate. Its creation date of June 03 2026 and immediate appearance on blocklists suggest a deliberate phishing campaign.
Infrastructure analysis shows the domain is hosted behind Cloudflare. It resolves to IP address 188.114.97.3, which is registered to Cloudflare, Inc. in Canada. The authoritative nameservers are dean.ns.cloudflare.com and emely.ns.cloudflare.com. Although the TLS handshake presents a certificate issued by Google Trust Services (WE1), the mismatch between the certificate and the domain triggers the 526 error, a common tactic used to bypass browser warnings while still delivering malicious payloads.
Threat intelligence feeds corroborate the malicious nature of the domain. VirusTotal records five out of ninety‑five security vendors flagging the site, and it appears on at least one public blocklist. The Gridinsoft trust score is 0 out of 100, reinforcing the assessment of a low‑reputation resource. PhishDestroy has already added the domain to its blocklist, indicating that upstream protection services are aware of the threat.
Defenders should immediately block was.becrown.life at the DNS and network layers, and add the associated IP 188.114.97.3 to deny lists. Continuous monitoring of Cloudflare‑hosted name servers for similar newly registered domains can help detect follow‑on campaigns. Organizations should also educate Binance users about the risk of invalid SSL warnings and encourage verification of legitimate Binance URLs before entering credentials.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: becrown.life
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain becrown.life behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога