bendavo[.]su
证据摘要
This domain, bendavo.su, is identified as a high-risk phishing infrastructure specifically designed to compromise cryptocurrency wallet credentials. Analysis indicates the site impersonates legitimate wallet interfaces, tricking users into entering private keys or seed phrases, which are then exfiltrated to attacker-controlled servers. The threat primarily targets users of decentralized finance (DeFi) platforms and self-custody wallets, where credential theft can result in immediate and irreversible asset loss. The domain’s design and functionality closely resemble authentic wallet services, increasing the likelihood of successful deception among less vigilant users. Infrastructure analysis reveals the domain was registered on March 26, 2026, through an anonymized registrar, a common tactic to obscure ownership and delay takedown efforts. As of the latest assessment, bendavo.su is flagged by 20 out of 95 security vendors on VirusTotal, indicating a broad consensus on its malicious nature. Additionally, the domain appears on four distinct security blocklists, further corroborating its classification as a phishing threat. The combination of recent registration, widespread detection, and blocklist inclusion underscores the domain’s active role in ongoing credential harvesting campaigns. Users who have interacted with bendavo.su are advised to take immediate remedial action. First, revoke any wallet permissions or connected applications associated with the domain via the wallet’s settings or a blockchain explorer. Second, transfer assets to a new wallet with a fresh seed phrase, as compromised credentials may still be exploited even after the domain is offline. Finally, monitor transaction histories for unauthorized activity and report the incident to relevant security teams or platforms to aid in broader mitigation efforts. Given the high-risk nature of this threat, affected users should assume their credentials are compromised and act accordingly.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | bendavo.su |
malicious | Sinkholed |
| DigiCert UltraDNS | bendavo.su |
malicious | Sinkholed |
| Hagezi Threat Feed | bendavo.su |
malicious | Sinkholed |
| DNS4EU | bendavo.su |
malicious | Sinkholed |
| Quad9 DNS | bendavo.su |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
监控中的外部数据源 7 个 无匹配
域名情报
技术详情DNS、TLS 名称和时间戳
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控