buildappeal-x[.]com
“Mamma.com Search - Trust Mamma to provide the best search results”
Сводка доказательств
buildappeal-x.com was registered on 23 February 2026 through Dynadot LLC and resolves to the IPv4 address 103.224.212.112, which is assigned to AS133618 (Trellian Pty. Limited) in the United States. The site presented the page title “Mamma.com Search – Trust Mamma to provide the best search results,” indicating an attempt to impersonate the Mamma.com search service. Technical fingerprinting shows the server runs Apache HTTP Server with PHP and includes client‑side libraries such as jQuery, jQuery UI, a jQuery CDN, Google Tag Manager, Google Analytics and the analytics platform Contentsquare. No TLS certificate was observed, leaving the site accessible only via plain HTTP.
The domain is currently listed as offline, but historical detections record it as a generic phishing campaign with an elevated risk level. Gridinsoft assigned a trust score of 0 out of 100. The domain appears on three security blocklists and has been flagged by one of ninety‑three vendors on VirusTotal. Additional blocking services including PhishDestroy, MetaMask and SEAL have reported the domain. The nameservers in use are 5014.ns1.abovedomains.com and 5014.ns2.abovedomains.com.
The intelligence classifies the activity as an investment scam, though no further details on the fraudulent payload are available. Defenders should continue to block the domain and its hosting IP, monitor the associated nameservers for future registrations, and consider adding the domain to internal deny lists. Because the site lacks encryption, any attempt to interact with it would expose credentials in clear text. Ongoing observation of the hosting ASN and related infrastructure is recommended to detect possible re‑use of the same server for new malicious campaigns.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260223-604123- Заголовок сохранённой страницы
- Mamma.com Search - Trust Mamma to provide the best search results
- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | obs.sd559908.js.rsocdomains.com |
malicious | Sinkholed |
| DNS4EU | obs.sd559908.js.rsocdomains.com |
malicious | Sinkholed |
| Quad9 DNS | obs.sd559908.js.rsocdomains.com |
malicious | Sinkholed |
| DigiCert UltraDNS | dynadot.rsocdomains.com |
malicious | Sinkholed |
| Quad9 DNS | dynadot.rsocdomains.com |
malicious | Sinkholed |
| DigiCert UltraDNS | ob.sd559908.js.rsocdomains.com |
malicious | Sinkholed |
| Quad9 DNS | ob.sd559908.js.rsocdomains.com |
malicious | Sinkholed |
| DNS4EU | ob.sd559908.js.rsocdomains.com |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
8 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
VirusTotal
1 → 2
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of buildappeal-x.com · checked Mar 2, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание