bs2tsait1[.]cc
证据摘要
This domain, bs2tsait1.cc, is identified as a credential theft phishing site designed to harvest sensitive login information from unsuspecting users. Analysis indicates the page mimics legitimate authentication portals, presenting a high risk of account compromise for individuals who interact with it. The domain was engineered to deceive users into submitting credentials, which are then exfiltrated to attacker-controlled infrastructure for unauthorized access or financial fraud. Infrastructure analysis reveals the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 26, 2026, and currently resolves to the IP address 188.114.97.3, hosted behind CloudFlare in Canada. The domain is flagged by 13 out of 95 security vendors on VirusTotal, and appears on one security blocklist. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the threat, as phishing sites commonly use valid certificates to appear legitimate. The page title 'Just a moment...' suggests the use of evasion techniques to delay or bypass automated detection systems. Users who visited bs2tsait1.cc or entered credentials on the site should immediately revoke any submitted information. Reset passwords for all accounts where the same credentials may have been reused, and enable multi-factor authentication where available. Monitor financial and account activity for unauthorized transactions or access attempts. If the domain was accessed in a corporate environment, report the incident to internal security teams for further investigation and containment. The domain's current offline status does not eliminate the risk, as compromised credentials may still be exploited.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
已存储的结果证据
处置结果与下线归因
- 结果
redirected- 可用性
reachable_redirect- 原因
http_redirect- 置信度
- 80%
- 首次观测
- 最新观测
证据 SHA-256 50fab3bf16c3
检测时间线
-
可用性
首次存储值:未知
993d00c35140 -
可用性
未知 → 已重定向
701c5e3fde49 -
可用性
已重定向 → 未知
c58a1a407531 -
可用性
未知 → 已重定向
93895c1f14b2 -
可用性
已重定向 → 未知
7cebcfd4071c -
可用性
未知 → 已重定向
e487c9733610 -
可用性
已重定向 → 未知
ca255b61650a -
可用性
未知 → 已重定向
c824728ddb31 -
可用性
已重定向 → 未知
d8f7d37d7f95 -
可用性
未知 → 已重定向
790baad69d47
显示全部(4)
-
可用性
已重定向 → 未知
afa49a2b04dd -
可用性
未知 → 已重定向
62b104a5f817 -
可用性
已重定向 → 未知
e70d6b0bd31a -
可用性
未知 → 已重定向
50fab3bf16c3
社区报告
由 1 名社区成员报告;首次发现于 2026年3月26日
- 已存储报告
- 1
- 已报告的唯一 URL
- 1
域名情报
技术详情DNS、TLS 名称和时间戳
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控