ultrabasefirmware[.]com
Résumé des preuves
Analysis of ultrabasefirmware.com indicates that the domain is part of a high‑risk crypto‑scam infrastructure that has been taken offline as of the report date. The domain was registered on 29 October 2025 through NiceNIC International Group Co., Limited and has never presented an SSL certificate, leaving all traffic unencrypted. DNS resolution points to 104.21.66.8, an address owned by Cloudflare, Inc. (AS13335) and located in the United States. Authoritative nameservers betty.ns.cloudflare.com and conrad.ns.cloudflare.com confirm the use of Cloudflare’s DNS services, a common choice for malicious operators seeking rapid deployment and concealment.
Multiple defensive feeds have flagged the domain: it appears on four security blocklists and has been actively blocked by PhishDestroy, Polkadot, Enkrypt, and Codeesura. Reputation scoring from Gridinsoft rates the domain at 0 out of 100, indicating an extreme lack of trust. VirusTotal analysis shows that 12 of 95 scanned security vendors flagged the domain, reinforcing the suspicion of malicious activity despite the relatively low detection count.
The identified scam type is a crypto‑scam, suggesting attempts to lure victims into fraudulent cryptocurrency transactions or credential harvesting. No HTTPS certificate, combined with the low trust score and blocklist presence, points to a deliberately low‑profile operation that relied on domain‑fronting through Cloudflare’s network.
Uncertainties remain regarding the exact payload or phishing kit employed, as no page title or content analysis is available. Consequently, defenders cannot confirm the specific phishing lure or the exact victim‑targeted brand. However, the convergence of registrar data, IP ownership, blocklist inclusion, and multi‑vendor detections provides a strong indication of malicious intent.
Recommendations for security teams include adding ultrabasefirmware.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
7 sources externes surveillées Aucune correspondance
Preuves du résultat enregistrées
Résultat et attribution du retrait
- Résultat
held- Disponibilité
unreachable- Cause
registrar_client_hold- Acteur
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mécanisme
client_hold- Confiance
- 95%
- Première observation
- Dernière observation
Indisponibilité estimée
Délai avant indisponibilité: 0 hSHA-256 de la preuve 41d5cee084b2
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
Disponibilité
Première valeur enregistrée : DNS inactif
f93a11f87e4d -
Disponibilité
DNS inactif → Inconnu
501692e04348 -
Disponibilité
Inconnu → Retenu
df0983cac1b0 -
Disponibilité
Retenu → Inactif
995a7b204fe0 -
Disponibilité
Inactif → DNS inactif
380ea940b28a -
Disponibilité
DNS inactif → Inconnu
42062a4dfe38 -
Disponibilité
Inconnu → Retenu
0b85443bbf55 -
Disponibilité
Retenu → Inconnu
381e819cadac -
Disponibilité
Inconnu → DNS inactif
6dfe9145995c
Tout afficher (7)
-
Disponibilité
DNS inactif → Retenu
a7482d130292 -
Disponibilité
Retenu → DNS inactif
641ed81dc4d5 -
Disponibilité
DNS inactif → Inconnu
143a35889305 -
Disponibilité
Inconnu → Retenu
f306eeaa7fbe -
Disponibilité
Retenu → Inconnu
76184d442cde -
Disponibilité
Inconnu → DNS inactif
d0b7046e8c2f -
Disponibilité
DNS inactif → Retenu
41d5cee084b2
Signalements communautaires
Signalé par 1 membre de la communauté ; première observation le 30/10/2025
- Signalements enregistrés
- 1
- URL signalées uniques
- 1
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif