# PhishDestroy threat dossier — cbase-ai-premium-edition.com ================================================================ Fetched: 2026-05-06 01:11:30 UTC Canonical: https://phishdestroy.io/domain/cbase-ai-premium-edition.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 88/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Coinbase ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/95 security vendors flagged this domain Flagging vendors: Bfore.Ai PreCrime, LevelBlue, Webroot ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 84.32.84.81 (LT, Vilnius) ASN: AS47583 Hostinger International Limited Hosting org: Hostinger CDN Registrar: HOSTINGER operations, UAB Nameservers: ns1.dns-parking.com, ns2.dns-parking.com Registered: 2025-08-22 Page title: Coinbase AI Wallet HTTP response: 530 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-07-17 Status: INVALID chain Fingerprint: 85deebd40462d3e71229815e4911426c861e45c5a4b7b8e12a14fad9e2728695 Subject Alternative Names (related infrastructure — often same operator): - www.cbase-ai-premium-edition.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-08-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-05 18:43:36 UTC (by PhishDestroy tracker) First reported: 2026-05-05 15:44:20 UTC (abuse notice filed) Last verified: 2026-05-06 01:50:02 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019df8ce-40c5-73af-8df4-8c2695f0e626/ URLQuery: https://urlquery.net/report/0278bd08-7f31-493f-bb77-363ddeff4cfe Wayback Machine: https://web.archive.org/web/*/cbase-ai-premium-edition.com crt.sh CT logs: https://crt.sh/?q=%25.cbase-ai-premium-edition.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=cbase-ai-premium-edition.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/cbase-ai-premium-edition.com URLhaus: https://urlhaus.abuse.ch/host/cbase-ai-premium-edition.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-05 18:44:34 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies cbase-ai-premium-edition.com as an active crypto drainer posing as a premium AI edition, targeting users seeking advanced tools. This domain, registered through HOSTINGER operations, UAB, was created on August 22, 2025, and resolves to IP 84.32.84.81. VirusTotal analysis reveals a concerning detection ratio, with 3 out of 95 security vendors flagging the site for malicious activity. The use of a Let’s Encrypt SSL certificate further lends credibility to the threat actor’s deception. The threat from cbase-ai-premium-edition.com is elevated due to its specific targeting of users interested in AI tools. While the exact number of confirmed victims remains undisclosed, the low but present detection rate on VirusTotal suggests this domain may have evaded broader scrutiny despite its malicious nature. The domain’s recent creation—just days ago—indicates a likely opportunistic campaign designed to capitalize on users searching for AI-related services. Technical indicators, including the IP resolution and registrar details, align with patterns observed in similar crypto drainer operations, which often exploit newly registered domains to avoid early detection. Users who have visited or interacted with cbase-ai-premium-edition.com should take immediate precautions. Disconnect from the internet if any transactions or sensitive data were accessed via the site. Scan all connected devices for malware, particularly focusing on browser extensions or wallet software that may have been compromised. Avoid reuse of passwords or crypto wallet credentials across other services. For ongoing protection, consider blocking the domain at the network level and reporting the activity to PhishDestroy for further analysis and blacklisting. Early intervention is critical to mitigate potential financial or data loss. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260505-871419 TLS cert SHA-256: 85deebd40462d3e71229815e4911426c861e45c5a4b7b8e12a14fad9e2728695 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/cbase-ai-premium-edition.com/ JSON API: https://api.destroy.tools/v1/check?domain=cbase-ai-premium-edition.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 146,041 domains (61,118 alive under monitoring, 84,662 confirmed takedowns/dead). Site: https://phishdestroy.io