buidlpad[.]help
Análisis de phishing y seguridad de buidlpad.help
“Buidlpad | Join the Revolution of Community-Driven Crypto”
buidlpad.help — Contenido no disponible (HTTP 502). Suplantación de marca: Discord; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 13/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); Google Safe Browsing flagged; PhishDestroy score 89/100. Registrador: NameSilo.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain buidlpad.help was registered through NameSilo, LLC on 23 September 2025. It resolves to the Cloudflare‑owned address 172.67.188.121, which is announced by AS13335 in the United States. The domain is served without an SSL certificate, indicating that HTTPS was not configured at the time of analysis. The authoritative nameservers are clyde.ns.cloudflare.com and lilyana.ns.cloudflare.com, confirming use of Cloudflare DNS.
The page title returned by the web server is “Buidlpad | Join the Revolution of Community‑Driven Crypto”, which does not reference the impersonated brand but the site is classified as a brand‑impersonation campaign targeting Discord. Google Safe Browsing has flagged the URL for social engineering, and Gridinsoft assigns a trust score of 0 / 100, reflecting extreme risk. VirusTotal reports that 13 of 95 scanned security vendors identified the domain as malicious, and the domain appears on a single external blocklist. PhishDestroy also lists the site as blocked.
The current operational status is offline, indicating that the content has been taken down or the host is no longer serving pages. Defenders should continue to block the domain at perimeter and DNS layers, monitor for any re‑hosting of the same host header, and add the associated IP 172.67.188.121 to deny lists where feasible. Because the domain leverages Cloudflare infrastructure, future clones may appear under different subdomains; threat‑intel feeds should be queried for newly observed aliases. Incident response teams should treat any credential‑capture attempts referencing Discord as potentially originating from this infrastructure and enforce multi‑factor authentication for affected accounts.
Señales de seguridad
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.