Binance phishing and impersonation - 11 domains observed
MalwareAnalyzer by Cyble has observed 11 distinct domains impersonating Binance across 13 URL scans. 11 of them carry a malicious or suspicious verdict, and the pages were built with the kit binance / crypto exchange kit. None of these domains belong to Binance; they are sites impersonating it, detected by comparing a page's claimed identity against evidence of who actually operates it.
Lookalike domains impersonating Binance
The domain itself is the deception on these: a homograph, typosquat or a Binance brand token built into the name, on infrastructure Binance does not operate.
| Domain | Worst verdict | Evidence | Scans | First seen | Last seen | Kit |
|---|---|---|---|---|---|---|
| binancemagazine.com | suspicious | brand token in domain | 1 | 2026-08-20 | 2026-08-20 |
Binance-branded phishing pages on compromised or third-party sites
These domains are NOT lookalikes of Binance - most are legitimate sites that have been compromised, or free-hosting space, serving a page that presents Binance branding in a credential or payment context. The domain owner is usually a victim too; each row is about the hosted page, never an accusation against the domain itself.
| Domain | Worst verdict | Evidence | Scans | First seen | Last seen | Kit | Example page |
|---|---|---|---|---|---|---|---|
| www.stefani.cz | suspicious | phishing kit | 1 | 2026-08-23 | 2026-08-23 | binance / crypto exchange kit | https://www.stefani.cz/fck/file/sifozopezetumojupaj.pdf |
| www.dewalt-naradi.cz | suspicious | phishing kit | 2 | 2026-08-23 | 2026-08-23 | binance / crypto exchange kit | https://www.dewalt-naradi.cz/?dedupqa=2 |
| whatsapp.ospexit.com | suspicious | phishing kit | 1 | 2026-08-22 | 2026-08-22 | binance / crypto exchange kit | https://whatsapp.ospexit.com/login |
| booking.tradetrak.com.au | malicious | phishing kit | 1 | 2026-08-22 | 2026-08-22 | binance / crypto exchange kit | https://booking.tradetrak.com.au/ |
| www.basraamazon.com | malicious | phishing kit | 1 | 2026-08-21 | 2026-08-21 | binance / crypto exchange kit | https://www.basraamazon.com/ |
| ayurvedaemart.com | malicious | phishing kit | 1 | 2026-08-21 | 2026-08-21 | binance / crypto exchange kit | https://ayurvedaemart.com/uploads/file/64598020074.pdf |
| bookingslikethis.com | suspicious | phishing kit | 1 | 2026-08-20 | 2026-08-20 | binance / crypto exchange kit | https://bookingslikethis.com/login |
| about.bookingsbnb.com | malicious | phishing kit | 1 | 2026-08-20 | 2026-08-20 | binance / crypto exchange kit | https://about.bookingsbnb.com/public/index.php/admin/login |
| jagatjyotischool.org | suspicious | phishing kit | 2 | 2026-08-15 | 2026-08-20 | binance / crypto exchange kit | http://jagatjyotischool.org/...erfiles/file/10744699010.pdf |
| booking.deque.se | suspicious | phishing kit | 1 | 2026-08-20 | 2026-08-20 | binance / crypto exchange kit | https://booking.deque.se/Account/Login?ReturnUrl=%2F |
Phishing kits used
- binance / crypto exchange kit - 12 scans
Malware observed hosted on or communicating with these domains
None yet. That is the honest state, not a gap in the page: credential-harvesting phishing mostly collects logins rather than serving executables, so a domain can be actively hostile with no malware ever hosted on it. This section fills in only when a sample's runtime traffic, extracted configuration or download provenance evidences one of these domains - a hostname merely appearing inside a file's bytes is listed separately below and never counted here.
Samples containing one of these hostnames as a string
These samples merely CONTAIN one of the impersonating hostnames somewhere in their bytes - an embedded blocklist, a configuration template or a bundled report produces the same observation - so this is NOT evidence the sample ever contacted the domain, and it is never counted as an attack on Binance.
- 05856b637b6148a7… (Phishing) - contains jagatjyotischool.org
- a161c8e1116af91c… (Phishing) - contains ayurvedaemart.com
- dc08af26a50499ed… (Phishing) - contains ayurvedaemart.com
- 71d91defa77a64b8… (Phishing) - contains jagatjyotischool.org
- 87cb7bbb810e583c… (Phishing) - contains jagatjyotischool.org
- 12c57499385babfb… (Phishing) - contains ayurvedaemart.com
- 8041ddc3e7962a16… (Phishing) - contains jagatjyotischool.org
- 1859b60a15a4672a… (Phishing) - contains jagatjyotischool.org
- 5ea8373e3717818f… (Phishing) - contains jagatjyotischool.org
- 5b918e4589ff7477… (Phishing) - contains ayurvedaemart.com
How impersonation is detected
A page's CLAIMED identity (its title, og:site_name, favicon and phishing-kit
fingerprint) is compared against evidence of who actually operates it: the certificate subject
organisation, the RDAP registrant and the announcing network. A free domain-validated certificate
asserts nothing about ownership, and that asymmetry is itself the signal. A page on Binance's
own apex with a matching certificate organisation is treated as the real property, not an
impersonation, which is why this list does not include Binance's own sites.
These are point-in-time observations. A domain listed here may since have been taken down, and absence from this list is not evidence a domain is safe.
Questions about Binance phishing
- How many domains are impersonating Binance?
- 11 distinct domains, seen across 13 public URL scans, of which 11 currently carry a malicious or suspicious verdict.
- How can I tell a fake Binance site from the real one?
- Compare what the page CLAIMS against who demonstrably operates it: the certificate subject organisation, the domain's registrant and the network announcing its address. A free domain-validated certificate proves control of the name and nothing about ownership, and that asymmetry is the signal - a real Binance property does not need to borrow the brand's look.
- Which phishing kits target Binance?
- binance / crypto exchange kit (12 scans). A kit fingerprint means the page was built from a known toolkit rather than hand-made, which usually indicates a campaign rather than a one-off.
- Is a domain safe if it is not listed here?
- No. This lists what MalwareAnalyzer has scanned, not the whole internet, and a domain taken down yesterday still appears. Absence is not evidence of safety - scan the specific URL.
All brands under attack · Scan a URL · Latest analyzed threats · How URL scanning works