ralvixen-it[.]net
“Ralvixen - Piattaforma Ufficiale Italia | Trading IA 2026”
Analysis of the domain ralvixen-it.net indicates it was actively impersonating Base, a known blockchain platform, as part of a brand impersonation scam targeting Italian-speaking users. The domain, created on February 21, 2026, resolved to IP address 172.67.145.115, hosted on Cloudflare's infrastructure (AS13335) in the United States. The page title, 'Ralvixen - Piattaforma Ufficiale Italia | Trading IA 2026,' suggests the site presented itself as an official Italian trading platform leveraging AI, likely to deceive users into engaging with fraudulent financial services. Infrastructure analysis reveals the domain lacked an SSL certificate, increasing the risk of unencrypted data transmission. It was registered through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently associated with high-risk domains.
Nameservers were hosted on Cloudflare (andronicus.ns.cloudflare.com and chan.ns.cloudflare.com), a common tactic to obscure hosting details and evade takedowns. As of the report date, the domain is offline, though its prior activity remains a concern. Detection data shows the domain was flagged by 18 of 95 security vendors on VirusTotal, a strong indicator of malicious intent. It also appeared on three security blocklists, including PhishDestroy, MetaMask, and SEAL, further corroborating its classification as a high-risk threat. Gridinsoft assigned a trust score of 0/100, reinforcing the assessment of malicious activity.
Defenders should treat this domain as compromised and block it at the network level. Given its association with Base impersonation, monitoring for similar domains using analogous naming conventions (e.g., regional modifiers, 'trading,' or 'IA' themes) is recommended. If the domain reactivates, immediate takedown requests should be pursued through Cloudflare and the registrar.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
PD-20260120-9CE125 Recipient: abuse-contact@publicdomainregistry.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive