benqi[.]cc
“Benqi”
证据摘要
The domain benqi.cc was registered on 21 February 2026 through Immaterialism Limited. It is currently active and resolves to the IPv4 address 37.27.135.61, which belongs to the Hetzner Online GmbH data centre in Finland (AS24940). The authoritative name servers are 1-you.njalla.no, 2-can.njalla.in, and 3-get.njalla.fo, all hosted by the njalla service. An HTTPS connection to benqi.cc presents a low‑trust certificate identified as R12, and the web server returns HTTP status 200. The landing page title is simply “Benqi”, matching the domain name and suggesting an attempt to mimic a legitimate brand. Gridinsoft assigns a trust score of 31 out of 100, indicating a high likelihood of malicious intent. The site is classified as a brand‑impersonation campaign targeting multiple brands, listed under the generic target “across”. It is tagged as a seed_phish operation and has been added to the PhishDestroy blocklist, with one additional security blocklist reference. VirusTotal analysis shows two out of ninety‑five scanners flagging the domain as malicious, reinforcing the suspicion. Defenders should proactively block DNS resolution for benqi.cc and any subdomains, enforce TLS inspection to capture the malicious payload, and consider sinkholing the associated IP address. Continuous monitoring of the njalla name servers is advised, as the infrastructure could be repurposed for other campaigns. At present, the content observed is limited to the generic “Benqi” landing page; further payloads may be delivered after user interaction.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控