equitycapitalmarket[.]co
“Crypto and Stock Trading with Equity Capital Market”
equitycapitalmarket.co — Inhalt nicht verfügbar. Zusammenfassung der Beweislage: VirusTotal 15/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); PhishDestroy score 100/100. Registrar: Sav.com.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain equitycapitalmarket.co was registered on 21 February 2026 through the registrar Sav.com LLC. DNS resolution points to the IPv4 address 185.255.122.10, which is allocated to Virtual Systems LLC in Ukraine (AS30860). The site presents a TLS certificate issued by Let’s Encrypt (R12) and serves HTTP responses with a 302 redirect, indicating an attempt to forward visitors to another location. The page title retrieved from the host reads “Crypto and Stock Trading with Equity Capital Market”, suggesting an investment‑oriented lure. Technology fingerprinting identifies the use of Smartsupp live‑chat widget, OWL Carousel, jQuery UI, jQuery, and support for HTTP/3, all of which are common in low‑cost website deployments. Reputation services flag the domain as extremely high risk.
Scamadviser assigns a trust score of 1 out of 100, Gridinsoft also reports a score of 1 out of 100, and the domain appears on a known phishing blocklist maintained by PhishDestroy. VirusTotal analysis shows that five of ninety‑three scanning engines have flagged the site, reinforcing the malicious assessment. AlienVault OTX lists the address in one threat‑intel pulse, and the domain is present on an additional security blocklist. The MX record is self‑referential (priority 0, host equitycapitalmarket.co), a pattern often used by phishing operators to control email flow. The evidence collectively points to a classic generic phishing operation that likely harvests credentials or financial information by masquerading as a legitimate crypto or stock trading service.
However, the exact payload, phishing landing pages, and victim interaction flow have not been publicly disclosed, leaving the precise modus operandi uncertain. Defenders should block both the domain and its resolving IP at perimeter defenses, monitor DNS queries for the associated nameservers (mars1.freednsdedi.com, mars2.freednsdedi.com), and add the IP to threat‑intel feeds.
Sicherheitssignale
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 5 identified
Live chat and visitor recording tool for customer support.
Touch-enabled jQuery plugin for responsive carousel sliders.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal-Analyse
Archivierte Beweise
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of equitycapitalmarket.co · checked Mar 2, 2026
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt