chaingpt[.]dev[.]buidl[.]so
“Buidl.so | A Global Community of Web3 Founders, Investors, & Mentors”
Détection enregistrée
Alerte de dissimulation
- Type de dissimulation
status_split- Score de dissimulation
- 1/6
Résumé des preuves
Analysis indicates that the domain chaingpt.dev.buidl.so was registered on May 28 2022 through NameCheap, Inc. The site is currently active and is listed as a Google brand‑impersonation campaign. The public page title observed is “Buidl.so | A Global Community of Web3 Founders, Investors, & Mentors,” which does not directly reference Google, suggesting that the malicious content may be delivered via hidden endpoints or redirects that have not been publicly disclosed. Network infrastructure shows the domain resolves to IP 76.76.21.93, which belongs to the Amazon.com, Inc. network (AS16509) and is hosted in the United States. The domain serves an HTTP 308 permanent redirect response, and TLS is provided by a Let’s Encrypt certificate (R13). DNS is managed by dns1.registrar-servers.com and dns2.registrar-servers.com. Detected web technologies include a Vercel hosting environment, the HSTS security header, and Google Analytics tracking scripts. Threat‑intel feeds report that six of ninety‑five VirusTotal scanners flagged the domain as malicious, and Gridinsoft assigns a trust score of 0 / 100. The domain appears on a single security blocklist and has been blocked by PhishDestroy, confirming active mitigation by at least one anti‑phishing service. The observed scam type is classified as tech‑support, aligning with typical credential‑harvesting tactics that target users seeking assistance with Google services. Open questions remain regarding the exact phishing payload, the presence of any credential‑capture forms, and whether additional subdomains are used to amplify the campaign. Defenders should block the domain at perimeter and DNS layers, monitor for outbound connections to the resolved IP, and enforce multi‑factor authentication for Google accounts to mitigate credential compromise. Continuous reconnaissance of the associated IP range and periodic re‑scanning of the domain are recommended to detect any changes in hosting or content.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of chaingpt.dev.buidl.so · checked Mar 2, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif