securebnb[.]in
“Official USDT Verification - BNB Smart Chain”
securebnb.in — 未验证. 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 6/91 (alphaMountain.ai, Emsisoft, Fortinet, Gridinsoft, Netcraft); PhishDestroy score 68/100. 注册商: GoDaddy.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of www.securebnb.in shows a newly registered domain created on 21 February 2026 via GoDaddy.com, LLC. The site resolves to the IP address 216.198.79.1, which belongs to Amazon.com, Inc. (AS16509) and is physically located in the United States. The host provides an HTTPS endpoint secured by a Let’s Encrypt certificate (R13) and advertises HTTP Strict Transport Security (HSTS). The web server reports a 200 HTTP status and the underlying platform is identified as Vercel. The page title delivered by the server is “Official USDT Verification - BNB Smart Chain,” aligning with the listed scam type of a crypto‑related fraud.
Threat intelligence sources have placed the domain on at least one security blocklist, and the PhishDestroy service has actively blocked it. VirusTotal scans show that two of ninety‑three security vendors have flagged the domain, indicating a low but non‑zero detection ratio. Nameserver configuration uses ns43.domaincontrol.com and ns44.domaincontrol.com, consistent with the GoDaddy registrar. While the available data confirms the domain’s association with a crypto‑scam infrastructure, the exact payload or credential‑gathering mechanisms have not been publicly disclosed.
The limited vendor detections suggest that the site may be employing techniques that evade many scanners, or that the content has not yet been fully analyzed. Defenders should treat the domain as hostile, enforce blocking at network perimeters, and add the IP address 216.198.79.1 to deny‑list rules. Continuous monitoring of threat‑intel feeds for additional detections, changes in blocklist status, and any observed phishing URLs is recommended. Organizations that handle USDT or BNB assets should educate users about the fraudulent title and advise them to verify URLs against official Binance resources before entering credentials.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。