bc-bonus[.]cfd
“Bc-bonus: Most Popular Online Crypto Casino Based on Blockchain”
bc-bonus.cfd — 内容不可用. 品牌冒充:Genericcrypto; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 17/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); URLQuery 1 alert; URLScan malicious verdict; PhishDestroy score 95/100. 注册商: Global Domain Group.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain bc-bonus.cfd was registered on May 25, 2026 through Global Domain Group LLC and is currently listed as offline. DNS resolution points to 188.114.97.3, an IP owned by Cloudflare, Inc. (AS13335) located in the United States. The authoritative nameservers are blair.ns.cloudflare.com and fred.ns.cloudflare.com, both belonging to Cloudflare's DNS infrastructure. The site presented the page title "Bc-bonus: Most Popular Online Crypto Casino Based on Blockchain," indicating a brand‑impersonation campaign targeting cryptocurrency enthusiasts. Analysis of the hosting environment shows the use of a Let’s Encrypt/E8 TLS certificate, which provides encryption but does not attest to the legitimacy of the content.
Security scanners have flagged the domain on multiple fronts. VirusTotal recorded 17 detections out of 91 scanners, confirming the presence of malicious indicators. Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on one external security blocklist. PhishDestroy has explicitly blocked the domain, reinforcing its classification as a phishing vector. The campaign appears to be built on the publicly known "Gambler Scam" phishing kit, which is commonly used to harvest credentials and monetary assets from victims seeking online gambling services.
While the site is offline, the infrastructure remains observable and could be re‑activated. Defenders should block the IP address 188.114.97.3 and the domain bc-bonus.cfd at network perimeter devices, update URL filtering policies to include the observed blocklist entries, and monitor for any related subdomains or future registrations that reuse the same nameservers or hosting provider. Continuous threat‑intel feeds should be consulted for any resurgence of the Gambler Scam kit, and incident response teams should be prepared to investigate credential‑theft attempts that reference the crypto casino theme.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | bc-bonus.cfd |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
SHORTDOT 域名区 · 公开证据
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告
PD-20260617-AF06D7 Recipient: abuse@globaldomaingroup.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。