valealupilor[.]com
Phishing- und Sicherheitsprüfung für valealupilor.com
“Database Error”
valealupilor.com — Inhalt nicht verfügbar (HTTP 502). Betrugstyp: Brand Impersonation. Zusammenfassung der Beweislage: VirusTotal 16/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 10 alerts; CF Radar malicious; PhishDestroy score 95/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, valealupilor.com, is flagged as a brand impersonation threat targeting Base, a cryptocurrency platform. Analysis indicates the site was designed to deceive users into disclosing sensitive credentials or wallet information by mimicking legitimate Base services. No explicit crypto drainer kit signatures were observed, but the infrastructure aligns with credential theft campaigns commonly deployed against blockchain users. The page title 'Database Error' suggests either a staging environment or a deliberate attempt to evade detection by presenting a non-functional facade. Infrastructure analysis reveals the domain was registered on February 21, 2026, through an undisclosed registrar, with resolution to the IP address 85.120.18.2, hosted under AS5606 (GTS Telecom SRL) in Romania. The SSL certificate, issued by Encryption Everywhere DV TLS CA - G1, provides basic encryption but lacks organizational validation, a common trait in phishing domains. Detection metrics show 16 out of 95 security vendors on VirusTotal flagged the domain as malicious, while it appears on two independent security blocklists. No Google Safe Browsing (GSB) entries were identified at the time of analysis, though this may reflect a lag in propagation rather than benign status. As of the latest assessment, valealupilor.com has been taken offline, likely due to registrar intervention or hosting provider action. Despite its inactive status, residual risk persists due to the domain's recent registration and prior malicious classification. Organizations and individuals are advised to monitor for re-registration attempts or shifts in hosting infrastructure. Users who interacted with the domain should assume credential exposure and initiate account audits, particularly for cryptocurrency wallets or services associated with Base. Proactive blacklisting of the IP 85.120.18.2 and domain in enterprise security tools is recommended to mitigate potential lateral movement or secondary attack vectors.
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | studiowebcore.top |
malicious | Sinkholed |
| Hagezi Threat Feed | studiowebcore.top |
malicious | Sinkholed |
| DigiCert UltraDNS | studiowebcore.top |
malicious | Sinkholed |
| DNS0 Zero | studiowebcore.top |
malicious | Sinkholed |
| OpenDNS | studiowebcore.top |
phishing | Phishing Block |
| CIRA Canadian Shield DNS | u.to |
malicious | Sinkholed |
| Cloudflare DNS | valealupilor.com |
malicious | Sinkholed |
| Hagezi Threat Feed | valealupilor.com |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | valealupilor.com |
malicious | Sinkholed |
| OpenDNS | valealupilor.com |
phishing | Phishing Block |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 2 identified
High-performance web server compatible with Apache configurations.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt