base-coiiinpro-learn-us-en[.]wstd[.]io
base-coiiinpro-learn-us-en.wstd.io — Belum terverifikasi. Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 14/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CyRadar, ESET); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 92/100. Registrar: NameCheap.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis of base-coiiinpro-learn-us-en.wstd.io indicates that the domain is actively associated with a high‑risk crypto‑draining phishing campaign. The domain resolves to 104.19.163.34, which belongs to Cloudflare’s AS13335 network and is physically located in the United States. Registration records show that the domain was created on 25 February 2022 through NameCheap, Inc., and it is served by the Cloudflare nameservers cosmin.ns.cloudflare.com and sandra.ns.cloudflare.com. The site presents a TLS certificate issued by Let’s Encrypt (certificate identifier E8), confirming the use of encryption but offering no legitimacy. HTTP requests return a 401 status code, suggesting that the backend requires authentication, a pattern commonly observed in credential‑harvesting portals.
Reputation services have flagged the domain on one security blocklist and Google Safe Browsing classifies it as a social‑engineering threat. Independent scanning on VirusTotal shows that 14 of 95 antivirus and URL‑reputation engines label the domain as malicious. Additional threat‑intel sources, including PhishDestroy, have blocked the domain. The Gridinsoft trust score of 0 / 100 further reflects its malicious nature. The intelligence categorizes the activity as a “Crypto Scam,” although no specific details about the payload or victim interaction have been disclosed.
Defenders should block any outbound connections to 104.19.163.34 and add the fully qualified domain name to local DNS deny lists. Email filtering rules should be updated to flag messages containing URLs that match the *.wstd.io suffix, especially those that reference the domain’s sub‑path pattern. Continuous monitoring of Cloudflare‑hosted infrastructure is advised, as the attacker may shift hosting to other IPs within the same ASN. Because the site is currently offline, investigators should preserve the existing indicators of compromise and await potential re‑activation before conducting deeper content analysis.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive