calyravellin[.]net
“Calyra Vellin - Plataforma Oficial | Trading IA 2026”
On July 23, 2026, the domain calyravellin.net was identified as an investment scam impersonating the 'base' brand. The site's page title, 'Calyra Vellin - Plataforma Oficial | Trading IA 2026,' suggests it was designed to appear as an official trading platform, potentially misleading users into believing it is associated with legitimate investment services. Analysis indicates that the domain was registered through PDR Ltd. d/b/a PublicDomainRegistry.com on February 21, 2026.
It is currently offline, with its nameservers set to lennon.ns.cloudflare.com and meiling.ns.cloudflare.com, and it resolves to the IP address 188.114.96.3, located in the United States under the ASN AS13335, which is owned by Cloudflare, Inc. The domain does not have an SSL certificate, which is a common characteristic of phishing sites, as it lacks the necessary security measures to protect user data. Google Safe Browsing has flagged the domain for social engineering, and it appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL. AlienVault OTX lists the domain in one threat intelligence pulse, further confirming its malicious nature.
The Gridinsoft trust score for the domain is 0/100, indicating a complete lack of trustworthiness. Defenders should ensure that their security solutions are updated to block this domain and warn users against visiting it, even though it is currently offline. The absence of an SSL certificate and the high number of flags from security vendors and blocklists strongly suggest that the domain was used for malicious purposes, and it should be treated with caution until further evidence is available.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive