buildappeal-x[.]com
“Mamma.com Search - Trust Mamma to provide the best search results”
Riepilogo delle prove
buildappeal-x.com was registered on 23 February 2026 through Dynadot LLC and resolves to the IPv4 address 103.224.212.112, which is assigned to AS133618 (Trellian Pty. Limited) in the United States. The site presented the page title “Mamma.com Search – Trust Mamma to provide the best search results,” indicating an attempt to impersonate the Mamma.com search service. Technical fingerprinting shows the server runs Apache HTTP Server with PHP and includes client‑side libraries such as jQuery, jQuery UI, a jQuery CDN, Google Tag Manager, Google Analytics and the analytics platform Contentsquare. No TLS certificate was observed, leaving the site accessible only via plain HTTP.
The domain is currently listed as offline, but historical detections record it as a generic phishing campaign with an elevated risk level. Gridinsoft assigned a trust score of 0 out of 100. The domain appears on three security blocklists and has been flagged by one of ninety‑three vendors on VirusTotal. Additional blocking services including PhishDestroy, MetaMask and SEAL have reported the domain. The nameservers in use are 5014.ns1.abovedomains.com and 5014.ns2.abovedomains.com.
The intelligence classifies the activity as an investment scam, though no further details on the fraudulent payload are available. Defenders should continue to block the domain and its hosting IP, monitor the associated nameservers for future registrations, and consider adding the domain to internal deny lists. Because the site lacks encryption, any attempt to interact with it would expose credentials in clear text. Ongoing observation of the hosting ASN and related infrastructure is recommended to detect possible re‑use of the same server for new malicious campaigns.
Istantanea delle prove inviate
- Inviato
- Voci del registro
- 1
- ID del caso
PD-20260223-604123- Titolo della pagina acquisita
- Mamma.com Search - Trust Mamma to provide the best search results
- Artefatto PDF
- Prova in PDF
Base giuridica
Testo completo delle prove
Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | obs.sd559908.js.rsocdomains.com |
malicious | Sinkholed |
| DNS4EU | obs.sd559908.js.rsocdomains.com |
malicious | Sinkholed |
| Quad9 DNS | obs.sd559908.js.rsocdomains.com |
malicious | Sinkholed |
| DigiCert UltraDNS | dynadot.rsocdomains.com |
malicious | Sinkholed |
| Quad9 DNS | dynadot.rsocdomains.com |
malicious | Sinkholed |
| DigiCert UltraDNS | ob.sd559908.js.rsocdomains.com |
malicious | Sinkholed |
| Quad9 DNS | ob.sd559908.js.rsocdomains.com |
malicious | Sinkholed |
| DNS4EU | ob.sd559908.js.rsocdomains.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
8 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
VirusTotal
1 → 2
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of buildappeal-x.com · checked Mar 2, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo