bestblast[.]pro
“bestblast.pro”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
Analysis of the domain bestblast.pro confirms active impersonation of the Blast cryptocurrency platform, a high-risk threat targeting users through brand deception. The domain was registered on February 21, 2026, via REGRU-RU, a registrar historically associated with malicious infrastructure. It currently resolves to the IP address 31.31.197.37, which is hosted on AS197695, operated by a Russian-based provider. This infrastructure has been linked to prior phishing campaigns, though direct attribution to a specific threat actor remains unverified. The site returns an HTTP 200 status code, indicating an active and operational webpage, while its SSL certificate, issued by GlobalSign nv-sa, provides a superficial layer of legitimacy. However, technical indicators strongly suggest malicious intent: Google Safe Browsing classifies the domain under SOCIAL_ENGINEERING, and 11 out of 95 security vendors on VirusTotal have flagged it as malicious. Additionally, the domain appears on a single security blocklist, though broader detection may be limited by its recent registration and targeted scope. Defenders should prioritize blocking access to bestblast.pro at the network level, particularly in environments where cryptocurrency-related services are utilized. The use of nameservers ns1.hosting.reg.ru and ns2.hosting.reg.ru further ties the domain to hosting infrastructure with a documented history of abuse. While the exact phishing kit or payload remains unconfirmed, the combination of brand impersonation, low detection rates, and registrar reputation warrants immediate mitigation. Organizations should monitor for related domains registered under the same registrar or resolving to the same IP range, as this campaign may represent a broader, ongoing operation.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога