chaingpt[.]dev[.]buidl[.]so
Проверка домена chaingpt.dev.buidl.so на фишинг и безопасность
“Buidl.so | A Global Community of Web3 Founders, Investors, & Mentors”
chaingpt.dev.buidl.so — Скрытый · достижимый (HTTP 308). Олицетворение бренда: Google; Тип мошенничества: Tech Support Scam. Сводка доказательств: VirusTotal 6/95 (ChainPatrol, SOCRadar); cloaking observed; PhishDestroy score 80/100. Регистратор: NameCheap.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis indicates that the domain chaingpt.dev.buidl.so was registered on May 28 2022 through NameCheap, Inc. The site is currently active and is listed as a Google brand‑impersonation campaign. The public page title observed is “Buidl.so | A Global Community of Web3 Founders, Investors, & Mentors,” which does not directly reference Google, suggesting that the malicious content may be delivered via hidden endpoints or redirects that have not been publicly disclosed. Network infrastructure shows the domain resolves to IP 76.76.21.93, which belongs to the Amazon.com, Inc. network (AS16509) and is hosted in the United States. The domain serves an HTTP 308 permanent redirect response, and TLS is provided by a Let’s Encrypt certificate (R13). DNS is managed by dns1.registrar-servers.com and dns2.registrar-servers.com. Detected web technologies include a Vercel hosting environment, the HSTS security header, and Google Analytics tracking scripts. Threat‑intel feeds report that six of ninety‑five VirusTotal scanners flagged the domain as malicious, and Gridinsoft assigns a trust score of 0 / 100. The domain appears on a single security blocklist and has been blocked by PhishDestroy, confirming active mitigation by at least one anti‑phishing service. The observed scam type is classified as tech‑support, aligning with typical credential‑harvesting tactics that target users seeking assistance with Google services. Open questions remain regarding the exact phishing payload, the presence of any credential‑capture forms, and whether additional subdomains are used to amplify the campaign. Defenders should block the domain at perimeter and DNS layers, monitor for outbound connections to the resolved IP, and enforce multi‑factor authentication for Google accounts to mitigate credential compromise. Continuous reconnaissance of the associated IP range and periodic re‑scanning of the domain are recommended to detect any changes in hosting or content.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comАнализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of chaingpt.dev.buidl.so · checked Mar 2, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание