beast-auth[.]com
Análisis de phishing y seguridad de beast-auth.com
“MrBeast | 1000 Creators”
beast-auth.com — Último activo conocido (HTTP 301). Suplantación de marca: Mrbeast; Tipo de estafa: Fake Airdrop. Resumen de las pruebas: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Registrador: Web Commerce Communica….
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
The domain beast-auth.com was registered on May 8 2026 through Web Commerce Communications Limited dba WebNic.cc. It is actively serving a web page whose title reads “MrBeast | 1000 Creators”, a clear attempt to mimic the well‑known MrBeast brand and lure victims with a purported giveaway. Infrastructure analysis shows the zone is delegated to the authoritative nameservers cody.ns.cloudflare.com and raegan.ns.cloudflare.com. DNS resolution returns the address 172.67.184.14, an IP hosted by a content‑delivery network located in Canada. The site presents a TLS certificate issued by a free certificate authority and returns HTTP 526, indicating an SSL handshake issue with the origin server. Multiple threat indicators corroborate malicious intent. The domain appears on three security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL. Google Safe Browsing flags it for SOCIAL_ENGINEERING, and VirusTotal records seven out of ninety‑five scanners marking the domain as malicious. AlienVault OTX references the domain in one pulse, and the Gridinsoft trust score is 0 / 100. The combination of brand impersonation and a fake‑giveaway narrative aligns with the reported scam type. Given the high‑risk rating and active status, defenders should treat beast‑auth.com as a confirmed fake‑giveaway impersonation targeting followers of MrBeast. Recommended controls include adding the domain to blocklists, enforcing URL filtering, monitoring TLS certificate changes, and educating end‑users about unsolicited giveaway links that reference the MrBeast brand.
Cobertura de los datos12 recorded checks
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.