base[.]walletportal[.]online
“Base Wallet Support - 24/7 Customer Service | Buy and Sell Cryptocurrency”
base.walletportal.online — المحتوى غير متوفر. انتحال العلامة التجارية: Base; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 12/93 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 86/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
On 23 July 2026, the domain base.walletportal.online was observed hosting a page whose title reads “Base Wallet Support – 24/7 Customer Service | Buy and Sell Cryptocurrency”. The title explicitly references the Base brand, confirming a brand‑impersonation attempt aimed at cryptocurrency users. The domain was registered on 21 February 2026 and resolves to the IPv4 address 102.209.117.148, which is announced by AS329184 and is geolocated to South Africa under Host Africa (Pty) Ltd. The host is presently offline, and the same IP appears on a single security blocklist. An SSL certificate labeled “R12” was presented for the site, indicating the use of HTTPS but providing no further validation of legitimacy.
VirusTotal analysis returned 12 positive detections out of 93 scanned security vendors, reinforcing the malicious assessment. The domain is also listed by the PhishDestroy blocklist, which specifically tags it as a brand‑impersonation vector. No additional intelligence such as Safe Browsing, OTX, or registrar details is available beyond the creation date and IP information. Given the limited but consistent indicators—brand‑targeted page title, multiple vendor detections, blocklist inclusion, and the hosting of an SSL‑protected site on a known South African IP—the infrastructure is likely being leveraged to harvest credentials or lure victims into crypto‑related fraud.
The offline status suggests the operators may be rotating hosts, a common tactic to evade takedown. Defenders should continue to block traffic to base.walletportal.online at perimeter devices, monitor outbound connections to the associated IP address, and add the domain to internal phishing‑filter lists. Threat‑hunters may query historical DNS and certificate transparency logs to identify any previous resolutions or related domains that share the same IP or certificate fingerprint.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب