MALICIOUS — CRITICAL
dtest[.]beta[.]bitstone[.]eu
As of July 25, 2026, the domain dtest.beta.bitstone.eu is flagged as a high-risk, active phishing domain primarily targeting account takeover.
- VirusTotal
- 11/91
- Blocklists
- No stored match
- 可用性
- 最后已知的活跃状态 · HTTP 302
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
dtest.beta.bitstone.eu — 最后已知的活跃状态 (HTTP 302). 诈骗类型:Account Takeover. 证据摘要: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, Emsisoft, Forcepoint ThreatSeeker); PhishDestroy score 93/100. 注册商: EuroDNS.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Analysis
As of July 25, 2026, the domain dtest.beta.bitstone.eu is flagged as a high-risk, active phishing domain primarily targeting account takeover. The domain is registered through EuroDNS S.A., a reputable registrar, which does not inherently indicate malicious intent but requires further scrutiny in the context of the domain's current activity. Infrastructure analysis reveals that the domain resolves to the IP address 136.243.153.62, which is located in Germany and is part of the ASN24940, managed by Hetzner Online GmbH. This hosting provider is known for its wide range of services, but the association with a high-risk domain suggests that the IP may be compromised or deliberately chosen by the threat actor for its reliability and low suspicion levels.
The domain employs an Apache HTTP Server, a common web server software, which is consistent with typical phishing infrastructure. The SSL certificate is issued by Let's Encrypt, a widely used and trusted certificate authority, which can lend a false sense of security to unsuspecting users. The HTTP status code 302 indicates a temporary redirect, which is often used in phishing attacks to guide victims to a malicious page or to obfuscate the original URL. Gridinsoft's trust score for the domain is 0/100, the lowest possible score, indicating a significant risk of malicious activity.
The domain appears on one security blocklist, specifically PhishDestroy, a notable indicator of its involvement in phishing activities. While the page title 'Account Suspended' suggests that the domain may impersonate a legitimate service's account suspension page, the exact content and targeted brand have not been fully analyzed. Defenders should implement immediate blocking measures and monitor for any related activity. Additionally, users should be warned against visiting the domain and should verify their accounts through official channels only.
数据覆盖范围12 recorded checks
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
Casino / Gambling License Verification
所用技术 · 1 identified
Most widely used open-source HTTP server software.
VirusTotal 分析
存档证据
证据与外部报告Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。