bitnexy[.]com
bitnexy.com 网络钓鱼与安全检查
“bitnexy.com”
bitnexy.com — 最后已知的活跃状态 (HTTP 200). 证据摘要: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Forcepoint ThreatSeeker, Gridinsoft); 1 external blocklist match (Enkrypt); PhishDestroy score 83/100. 注册商: Dynadot.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
bitnexy.com was registered on February 21, 2026 through Dynadot LLC. The domain resolves to the IP address 199.59.243.228, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in the United States. HTTP requests return a 200 status code, and the site presents a page title of 'bitnexy.com'. No TLS certificate is observed, indicating the service is delivered over plain HTTP. Multiple security feeds have flagged bitnexy.com as malicious. VirusTotal reports that 5 out of 95 scanned vendors have flagged the domain, and Gridinsoft assigns a trust score of 0 out of 100. The domain appears on two public blocklists and has been added to the PhishDestroy and Enkrypt blocklists. AlienVault OTX records the domain in two separate threat intelligence pulses, reinforcing its association with phishing activity. The authoritative nameservers for the domain are piers.ns.cloudflare.com and samara.ns.cloudflare.com, both operated by Cloudflare. This configuration provides resilience and fast DNS resolution, a pattern commonly observed in malicious infrastructure. The hosting on Amazon's network combined with Cloudflare DNS suggests a low-cost, quickly provisioned service intended for short‑term campaigns. Beyond the metadata, the actual content served by bitnexy.com has not been publicly disclosed in the available intelligence. The page title matches the domain, but no further analysis of login forms, payloads, or credential harvesting mechanisms is present. Consequently, the specific phishing vector, targeted brands, or victim demographics remain unknown. Defenders should prioritize immediate blocking of bitnexy.com at network perimeter and DNS filtering layers. Continuous monitoring of the associated IP address 199.59.243.228 is advised, as the host may be repurposed for additional malicious domains. Threat‑intel teams should enrich future observations with content analysis to determine the exact phishing methodology and update detection signatures accordingly.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告
“Angel drainer”
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。