base-coiiinpro-learn-us-en[.]wstd[.]io
base-coiiinpro-learn-us-en.wstd.io — Непроверенный. Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 14/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CyRadar, ESET); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 92/100. Регистратор: NameCheap.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of base-coiiinpro-learn-us-en.wstd.io indicates that the domain is actively associated with a high‑risk crypto‑draining phishing campaign. The domain resolves to 104.19.163.34, which belongs to Cloudflare’s AS13335 network and is physically located in the United States. Registration records show that the domain was created on 25 February 2022 through NameCheap, Inc., and it is served by the Cloudflare nameservers cosmin.ns.cloudflare.com and sandra.ns.cloudflare.com. The site presents a TLS certificate issued by Let’s Encrypt (certificate identifier E8), confirming the use of encryption but offering no legitimacy. HTTP requests return a 401 status code, suggesting that the backend requires authentication, a pattern commonly observed in credential‑harvesting portals.
Reputation services have flagged the domain on one security blocklist and Google Safe Browsing classifies it as a social‑engineering threat. Independent scanning on VirusTotal shows that 14 of 95 antivirus and URL‑reputation engines label the domain as malicious. Additional threat‑intel sources, including PhishDestroy, have blocked the domain. The Gridinsoft trust score of 0 / 100 further reflects its malicious nature. The intelligence categorizes the activity as a “Crypto Scam,” although no specific details about the payload or victim interaction have been disclosed.
Defenders should block any outbound connections to 104.19.163.34 and add the fully qualified domain name to local DNS deny lists. Email filtering rules should be updated to flag messages containing URLs that match the *.wstd.io suffix, especially those that reference the domain’s sub‑path pattern. Continuous monitoring of Cloudflare‑hosted infrastructure is advised, as the attacker may shift hosting to other IPs within the same ASN. Because the site is currently offline, investigators should preserve the existing indicators of compromise and await potential re‑activation before conducting deeper content analysis.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание