asilfinspirex-invest[.]com
“Asil Finspirex - Resmi Platform | AI Ticaret 2025 | 10.000'den Fazla Yorum”
asilfinspirex-invest.com — Контент недоступен (HTTP 502). Олицетворение бренда: Binance; Тип мошенничества: Investment Scam. Сводка доказательств: VirusTotal 2/93 (Bfore.Ai PreCrime, SOCRadar); PhishDestroy score 56/100. Регистратор: Metaregistrar BV.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
On 24 July 2026, the domain asilfinspirex-invest.com was observed to be offline but retains multiple indicators of a brand‑impersonation investment scam targeting Binance users. The domain was registered on 21 February 2026 through Metaregistrar BV and points to the IP address 104.21.78.103, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. Both authoritative nameservers, brenda.ns.cloudflare.com and kirk.ns.cloudflare.com, resolve to Cloudflare infrastructure, indicating the use of a reputable CDN to mask the original hosting location. No TLS certificate was presented for the domain, suggesting that HTTPS was not enforced at the time of collection. The page title retrieved during analysis reads "Asil Finspirex - Resmi Platform | AI Ticaret 2025 | 10.000'den Fazla Yorum," which is unrelated to Binance but aligns with the claimed investment‑related narrative.
VirusTotal scanned the domain and recorded detections from 2 of 93 security vendors, and the domain appears on a single external blocklist. Gridinsoft assigned a trust score of 0 out of 100, reinforcing the malicious assessment. The domain has been reported to and blocked by PhishDestroy, and its status is currently listed as offline. The available evidence confirms that the domain was deliberately created to masquerade as a Binance‑related investment platform, leveraging a generic financial‑oriented page title to lure victims. However, the exact content served to end users, including any credential‑capture forms or payment instructions, has not been captured because the site is offline.
Consequently, the precise phishing or malware delivery mechanisms remain unknown. Defenders should continue to block the domain at DNS and proxy layers, monitor for any resurgence of the same hostnames or IP address, and add the IP 104.21.78.103 to threat‑intel feeds that track Cloudflare‑based malicious infrastructure.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260107-01D23D Recipient: abuse@metaregistrar.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание