MALICIOUS — HIGH
circuitcoreshifts[.]com
1 of 95 security engines flagged the domain; the latest stored check returned HTTP 502.
- VirusTotal
- 1/95
- Blocklists
- No stored match
- 가용성
- 콘텐츠를 사용할 수 없음 · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
circuitcoreshifts.com — 콘텐츠를 사용할 수 없음 (HTTP 502). 브랜드 사칭: Base; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 1/95 (Gridinsoft); PhishDestroy score 55/100. 등록기관: Atak Domain.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Evidence Digest
circuitcoreshifts.com is classified high with an evidence score of 55/100. 1 of 95 security engines flagged the domain. Registered 2 Feb 2025 via Atak Domain, hosted on 198.12.66.123 (AS-COLOCROSSING, US, US). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture.
Stored generated summary (templated)cerebras · 2026년 7월 24일
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis of circuitcoreshifts.com indicates a confirmed brand‑impersonation operation targeting the Base brand. The domain was registered on February 2, 2025 through Atak Domain and is hosted on IP address 198.12.66.123, which belongs to AS36352 (HostPapa) in the United States. DNS resolution points to nameservers ns1.host-forest.com and ns2.host-forest.com. No SSL certificate is presented for the site, a common characteristic of fraudulent pages that rely on unsecured HTTP connections.
The page title returned by the server is "Secure and Easy Way To Earn," which does not reference the victim brand but aligns with typical lure phrasing used in credential‑harvesting campaigns. Reputation services assign a Gridinsoft trust score of 0 / 100 and a Scamadviser score of 45 / 100, reflecting a low level of trust. The domain appears on a single security blocklist and is actively blocked by PhishDestroy, confirming that at least one defensive feed has identified the site as malicious. VirusTotal analysis shows that 1 of 95 scanning engines flagged the domain, providing additional independent corroboration of its malicious nature.
Current operational status is offline, but the infrastructure remains observable and could be re‑activated. Defenders should continue to block the domain and its associated IP address, monitor the host‑Papa ASN for related activity, and include the nameservers in threat‑intel feeds. Because the site lacks TLS, any future re‑hosting would likely continue to use HTTP, simplifying detection. Continuous re‑evaluation of the domain’s status is advised, as offline phishing sites are frequently resurrected under new subdomains or with minor modifications.
데이터 적용 범위13 recorded checks
보안 신호
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 분석
증거 및 외부 보고서Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.