claim[.]humafinance[.]co
claim.humafinance.co — لم يتم التحقق منها. نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 2/91 (CRDF, Gridinsoft); PhishDestroy score 63/100. مسجّل النطاق: PDR.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
claim.humafinance.co was registered on March 06, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. The domain resolves to the Cloudflare‑owned address 172.67.137.230, which is associated with AS13335 in the United States. The TLS certificate is issued by Let’s Encrypt (E8), and the site presents the generic page title “Just a moment…”. The HTTP response code is 403, indicating that access to the underlying resource is currently denied.
Infrastructure analysis shows the domain is served behind Cloudflare, with Browser Insights, HTTP/3 support, and the authoritative nameservers johnathan.ns.cloudflare.com and sierra.ns.cloudflare.com. Reputation services have assigned a Gridinsoft trust score of 0 out of 100, and the domain appears on a single security blocklist. It is explicitly blocked by PhishDestroy. VirusTotal scans return 0 detections out of 95 engines, which does not imply safety given the other indicators.
The intelligence classification identifies this host as a cryptocurrency‑related “crypto drainer” campaign. The 403 status, combined with the generic page title, suggests a front‑end that may be used to host malicious scripts or to redirect victims after initial credential capture. No public samples or payload hashes have been released, so the exact mechanism for draining cryptocurrency remains unknown. The active flag and the presence on a blocklist indicate ongoing operation.
Defenders should add claim.humafinance.co and its resolving IP 172.67.137.230 to network deny lists and monitor outbound connections for HTTP/3 traffic to Cloudflare edge nodes serving this domain. Continuous re‑scanning on VirusTotal or similar platforms is advised, as detection scores may change. Logging of TLS handshake details and alerting on any attempt to retrieve the “Just a moment…” page can provide early indicators of infection attempts. Given the low trust score and active blocklist status, precautionary blocking is recommended pending further forensic investigation.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب