pump-cashbacks[.]fun
فحص التصيد والأمان للنطاق pump-cashbacks.fun
“Pump.fun Cashback | Get 30% Back on Rug Pull Losses”
pump-cashbacks.fun — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Pump.fun; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VT 2/94 (Fortinet, SOCRadar); URLQuery 0; URLScan no malicious verdict; GSB no flag; Spamhaus DBL_PHISH; BL 2 (MetaMask, SEAL); cloaking observed; PD 78/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy first observed pump-cashbacks.fun on Mar 25, 2026. Positive findings were recorded by VirusTotal, MetaMask, SEAL, and Spamhaus DBL. Evidence score: 78/100.
VirusTotal recorded 2 detections among 94 engines: Fortinet, SOCRadar on Mar 25, 2026 at 00:37 UTC. The external blocklist snapshot contained 2 matches (MetaMask, SEAL) on Aug 7, 2026 at 14:20 UTC. Spamhaus DBL: DBL_PHISH on Jul 13, 2026 at 22:36 UTC. URLQuery recorded no positive detection. On Mar 25, 2026 at 00:37 UTC, Google Safe Browsing returned no flag; PhishStats returned no feed match. URLScan completed without a malicious verdict (score 0).
HTTP 502 was recorded on Aug 7, 2026 at 01:36 UTC; content was unavailable. Latest classified outcome: registration hold observed; cause registrar client hold; mechanism client hold; observed actor NICENIC INTERNATIONAL GROUP CO., LIMITED on Aug 7, 2026 at 02:12 UTC. Registration records list NICENIC INTERNATIONAL GROUP CO., LIMITED as the registrar and Mar 24, 2026 as the registration date. At collection time, the domain resolved to 172.67.151.248. Collected metadata identifies Pump.fun as the apparent target. Captured page title: “Pump.fun Cashback | Get 30% Back on Rug Pull Losses”. PhishDestroy classified the observed content as Brand Impersonation. DOM analysis completed on Jul 29, 2026 at 04:04 UTC; stored DOM score 78/100. IoC extraction completed on Aug 1, 2026 at 04:21 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis25/03/2026
PhishDestroy identifies active crypto drainer domain pump-cashbacks.fun impersonating cashback reward programs. This domain is currently under investigation with an active threat status.
This domain was registered on March 24, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED. It resolves to IP 172.67.151.248 and holds a Let's Encrypt SSL certificate. PhishDestroy notes no VirusTotal vendors (2 of 95) have flagged this domain as of the current analysis, indicating a low initial detection rate. The domain's age, infrastructure choices, and lack of blocklist presence suggest either a newly deployed threat or a sophisticated evasion strategy.
Given its status as an active crypto drainer impersonating legitimate cashback programs, PhishDestroy assesses this domain as HIGH RISK. Users should avoid interacting with pump-cashbacks.fun and verify any reward-related communications through official channels. Recommendations include blocking the domain at network and endpoint levels, scanning systems for unauthorized crypto wallet connections, and reporting any suspicious activity to PhishDestroy for further analysis. Enhanced monitoring of outbound traffic to 172.67.151.248 is advised.
استخبارات أمن الشبكات Registrar Integrity Alert
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
حصلت ICANN على أموالها. أما المساءلة فلم تصل.
بالنسبة إلى نطاق gTLD هذا، يعمل المسجّل المذكور أعلاه بموجب عقد مع ICANN. وتحصّل ICANN رسوماً سنوية ومتغيرة ورسومًا قائمة على المعاملات مرتبطة بعمليات التسجيل والتجديد والنقل.
الاعتماد: جرت الاستفادة منه مالياً. المساءلة: يُرجى التحقق مرة أخرى لاحقاً.
ثم يبدأ السحر: تكتب ICANN البند RAA §3.18، ويتولى المسجّل التحقيق في إساءة الاستخدام داخل قاعدة عملائه، ويقدّم الضحايا الأدلة مجاناً، بينما تنتظر كل طبقة أن يتحرك طرف آخر. إذا كان ذلك يجعل الضحايا يشعرون بمزيد من الأمان، فممتاز—لقد أدّت الفاتورة مهمتها.
Latest Classified Outcome 2026-08-07 04:12:22 UTC
التقنيات · 5 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Progressive JavaScript framework for building user interfaces.
Hybrid Vue framework for server-side rendering and static sites.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of pump-cashbacks.fun · checked Mar 25, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
حول هذا التقرير: pump-cashbacks.fun
يقدم هذا التقرير أحدث الأدلة المخزنة المتاحة لـ PhishDestroy. يتم عرض الطوابع الزمنية للمصدر حيثما كان ذلك متاحًا؛ يمكن أن تتغير أحكام التوفر والبائعين بعد التجميع.
عرض الموقع الذي تم التقاطه عنوان الصفحة “Pump.fun Cashback | Get 30% Back on Rug Pull Losses” وربما ينتحل شخصية Pump.fun.
اعتبارًا من 07/08/2026، كان لدى pump-cashbacks.fun اكتشافات من محركات الأمان 2.
إذا كنت تعتقد أن هذه القائمة غير دقيقة، تقديم استئناف. للتعرف على منهجيتنا، قم بزيارة صفحة الأسئلة الشائعة.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب