swiftfxbase247[.]click
“swiftfxbase247 | CFD Trading — Trading on Stocks, Gold, Oil, Indices”
swiftfxbase247.click — Contenido no disponible (HTTP 502). Suplantación de marca: Genericscam; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 5 detections (engine total unavailable) (Google Safebrowsing, Lionic, Netcraft, SOCRadar, desenmascara.me); URLScan malicious verdict; Google Safe Browsing flagged; Spamhaus DBL_SPAM; PhishDestroy score 80/100. Registrador: OwnRegistrar.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain swiftfxbase247.click was registered on March 11, 2026 through OwnRegistrar, Inc. and currently resolves to the IP address 192.142.10.129, which is hosted in the Netherlands under AS214036 (Ultahost, Inc.). The site is offline at the time of analysis, but historical evidence shows it was flagged by multiple defenses. Google Safe Browsing classifies the URL as a social engineering threat, and PhishDestroy lists the domain on its blocklist. VirusTotal reports that five out of ninety‑five scanning engines flagged the domain, indicating malicious behavior despite the relatively low detection ratio.
The page title captured during the brief crawl reads “swiftfxbase247 | CFD Trading — Trading on Stocks, Gold, Oil, Indices,” suggesting a brand‑impersonation campaign aimed at traders interested in contract‑for‑difference products. Technical fingerprints include the use of YouTube embeds, Tailwind CSS, LiteSpeed web server, Alpine.js, Unpkg, jQuery CDN, and the live‑chat widget Chaport, all of which are commonly employed by low‑cost phishing kits to emulate legitimate trading platforms. Nameservers are split between cprapid.com and ecositewebhost.com, a pattern often seen in short‑lived malicious deployments. No SSL certificate is present, exposing any traffic to passive interception.
While the site is presently taken offline, the combination of blocklist placement, Safe Browsing flag, partial VirusTotal detections, and the brand‑impersonation page title justifies an elevated risk rating. Defenders should continue to block the domain at perimeter filters, monitor the IP 192.142.10.129 for any resurgence, and update internal threat intel with the observed indicators of compromise. Additional investigation is recommended to determine whether the associated nameservers are being reused for other fraudulent domains and to verify if any residual payloads were delivered before takedown.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 9 identified
Utility-first CSS framework for rapid custom UI development.
High-performance web server compatible with Apache configurations.
Lightweight JavaScript framework for composing behavior directly in markup.
Fast CDN for everything on npm — serves raw files from npm packages.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Datos y informes externos
PD-20260311-50D3CF Recipient: abuse@ownregistrar.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.