Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@hetzner.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
agrosabor[.]ec
“Agrosabor S.A.”
agrosabor.ec was registered on 2025-01-08 and is currently hosted on a Hetzner server in Germany (AS24940). The domain resolves to 167.235.182.68 and uses the name servers ns17.hostingcolor.com, ns18.hostingcolor.com, and ns19.hostingcolor.com. The site presents a page titled “Agrosabor S.A.” and serves content over HTTPS with a Let’s Encrypt certificate. Technical fingerprints show an Apache HTTP server running PHP, with front‑end libraries including Bootstrap, jQuery, Modernizr, and Google Maps integration. The domain appears on one security blocklist and has been flagged by PhishDestroy. VirusTotal records 15 of 95 scanned security vendors marking the site as malicious. Independent trust scoring services assign a Gridinsoft score of 0/100 and a Scamadviser score of 1/100, indicating extremely low credibility. The MX record points to agrosabor.ec itself, which is consistent with a minimal email setup often used by fraudulent operators. Analysis classifies the site as a cryptocurrency‑focused brand‑impersonation campaign targeting the brand “base”. The page mimics legitimate branding while directing visitors toward illicit cryptocurrency transactions. The combination of a recent registration date, low trust scores, and the presence of a known blocklist entry suggests an active high‑risk operation. Publicly available information does not reveal the exact content of the fraudulent pages or the payment mechanisms employed, leaving the full scope of the scam uncertain. Defenders should block the domain at network perimeters, update email filters to reject messages referencing agrosabor.ec, and monitor DNS queries for the associated IP address and name servers. Continuous re‑scanning with multi‑engine services is advised to capture any changes in the site's behavior. Organizations using the “base” brand should issue user warnings and enforce strict verification of any cryptocurrency requests originating from this domain.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/64/4d/intl/es_419/common.js |
audit | Hunting_JS_WebAssembly |
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/64/4d/common.js |
audit | Hunting_JS_WebAssembly |
| OpenDNS | agrosabor.ec |
phishing | Phishing Block |
| Hagezi Threat Feed | agrosabor.ec |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Technologies · 6 identified
Google Maps is a web mapping service. It offers satellite imagery, aerial photography, street maps, 360° interactive panoramic views of streets, real-time traffic conditions, and route planning for traveling by foot, car, bicycle and air, or public transportation.
maps.google.com 100% confidenceBootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 100% confidenceApache is a free and open-source cross-platform web server software.
httpd.apache.org 100% confidenceModernizr is a JavaScript library that detects the features available in a user's browser.
modernizr.com 100% confidencejQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of agrosabor.ec · checked Mar 18, 2026
Evidence & External Reports
PD-20260318-8B74CF Recipient: abuse@hetzner.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive