wweb-baseiinetmx[.]xyz
“Base Banco”
wweb-baseiinetmx.xyz — 内容不可用 (HTTP 502). 品牌冒充:Base; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 14 detections (engine total unavailable) (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 92/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain wweb-baseiinetmx.xyz was registered on February 21, 2026 and is presently taken offline, yet multiple security controls continue to flag it as malicious. Infrastructure analysis shows the domain resolves to the IP address 209.127.184.165, which is announced by AS55286 belonging to B2 Net Solutions Inc. in the United States. The SSL certificate presented by the host is self‑signed and lists "localhost" as the common name, a typical indicator of a hastily configured phishing or scam site. VirusTotal has logged 14 detections out of 95 scanned engines, confirming that a substantial portion of major anti‑malware vendors consider the domain malicious.
Additional reputation data includes a Gridinsoft trust score of 0 / 100 and placement on a single security blocklist, reinforcing the low trust posture. The site title returned by HTTP requests is "Base Banco," and the domain is explicitly attributed to a brand impersonation of "base" while the scam type is identified as a crypto scam. The domain is also listed as blocked by the PhishDestroy feed, indicating active community mitigation.
Defenders should immediately add 209.127.184.165 to network deny lists, enforce DNS sink‑hole rules for wweb-baseiinetmx.xyz, and ensure that web‑proxy and email security solutions reference the observed blocklist entry. Continuous monitoring of the IP range associated with AS55286 is recommended, as threat actors may reuse the same hosting environment for future campaigns. Although the site is offline, the combination of a self‑signed certificate, multiple vendor detections, low trust score, and explicit brand impersonation warrants an elevated risk rating and proactive defensive actions.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。