based-investment.com
“Home”
based-investment.com — Последний известный активный (HTTP 200). Олицетворение бренда: Coinbase; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 13/90 (ChainPatrol, alphaMountain.ai, BitDefender, ESET, Forcepoint ThreatSeeker); Spamhaus DBL_PHISH; PhishDestroy score 100/100. Регистратор: Ultahost.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
The domain based-investment.com was registered on 30 November 2024 through Ultahost, Inc. It resolves to the IPv4 address 75.127.1.122, which belongs to AS36352 operated by HostPapa in the United States. The authoritative nameservers are dm1.ourdns.site and dm2.ourdns.site. Reputation services assign it a Gridinsoft trust score of 0/100 and a Scamadviser score of 1/100, and it appears on a single security blocklist. The site is currently reachable over HTTPS with a certificate issued by Google Trust Services (WE1), and the HTTP response code is 200.
A passive fingerprint of the web server shows a stack that includes PHP, Bootstrap, jQuery, Google Hosted Libraries, FancyBox, GSAP, Smartsupp, and an embedded Google Maps component. The page title returned by the server is “Home”. Email services are directed to mail.based-investment.com with MX priority 10. VirusTotal analysis records eight detections out of ninety‑five scanners, and the domain is listed as blocked by PhishDestroy. The domain is explicitly tagged as a cryptocurrency‑related scam that impersonates the Coinbase brand.
Analysis cannot confirm the exact content or user‑experience of the site because no visual inspection was performed; therefore the presence of credential‑harvesting forms or other malicious payloads remains uncertain. Defenders should treat the domain as high‑risk given its low trust scores, active SSL, and confirmed brand‑impersonation flag. Recommended actions include adding 75.127.1.122 to network blocklists, configuring email gateways to reject or quarantine messages from mail.based-investment.com, and monitoring DNS queries for the domain and its nameservers. Continuous re‑evaluation is advised as additional intelligence, such as new VirusTotal detections or changes in hosting, may emerge.
Сигналы безопасности
Forensic History & Detection Timeline
-
VirusTotal Detections Update Mar 7, 2026 · 03:42 UTCVirusTotal scanner detections updated from 8 to 7. Added scanner alerts: ADMINUSLabs. Resolved alerts: Lionic, Seclookup.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сбор доказательств
Статус в публичных блок-листах
Сохранённый снимок · 2 sources
Аналитика доменов
Технические деталиDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 11 identified
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
Live chat and visitor recording tool for customer support.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of based-investment.com · checked Mar 6, 2026
Данные сообщества
2 сообщения сообщества
КатегорияOTHER_INVESTMENT_SCAM
Сообщения сообщества
Сообщил 1 участник сообщества; впервые замечено 03.09.2025
- Сохранённые сообщения
- 1
- Уникальные URL
- 1
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание