MALICIOUS — CRITICAL
فحص التصيد والأمان للنطاق backfoundation.cc
backfoundation[.]
This domain, backfoundation.cc, was identified as part of a high-risk phishing infrastructure targeting users through an NFT scam.
- VirusTotal
- 15/94
- Blocklists
- 3 · MetaMask, ScamSniffer
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
backfoundation.cc — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Genericcrypto; نوع الاحتيال: Nft Scam. ملخص الأدلة: VirusTotal 15/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_PHISH; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 95/100. مسجّل النطاق: Web Commerce Communica….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
This domain, backfoundation.cc, was identified as part of a high-risk phishing infrastructure targeting users through an NFT scam. Registered on March 17, 2026, via Web Commerce Communications Limited (WebNic.cc), the domain resolved to the IP address 188.114.97.3, hosted by Cloudflare, Inc. in Canada. Analysis of the domain's infrastructure reveals the use of Cloudflare nameservers (elsa.ns.cloudflare.com and kirk.ns.cloudflare.com) and technologies including React, jQuery, HSTS, and HTTP/3, alongside Cloudflare Browser Insights for potential performance monitoring. The page title, 'IPOs Onchain – Access IPO Allocations | Backpack,' suggests an attempt to impersonate or exploit the Backpack brand, likely to deceive users into engaging with fraudulent IPO or NFT-related offers.
The domain has been flagged by 15 of 94 security vendors on VirusTotal and appears on four security blocklists, including PhishDestroy, MetaMask, ScamSniffer, and SEAL. Gridinsoft assigned a trust score of 0/100, further indicating malicious intent. No SSL certificate was detected, increasing the risk of interception or manipulation of user data. As of July 24, 2026, the domain is offline, though its prior activity and infrastructure remain a concern for defenders.
Defenders should treat this domain as confirmed malicious infrastructure. Blocking access at the DNS or network level is recommended, along with monitoring for related domains registered through the same registrar or utilizing similar Cloudflare-hosted infrastructure. Given the domain's association with NFT scams, users should be alerted to potential risks of interacting with similar sites, particularly those promoting IPO allocations or on-chain financial opportunities. Further analysis of historical WHOIS records or passive DNS data may reveal additional linked infrastructure or campaign patterns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | backfoundation.cc |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 7 identified
JavaScript library for building user interfaces with component-based architecture.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of backfoundation.cc · checked Mar 21, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260321-CF7A38 Recipient: compliance_abuse@webnic.cc Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.