MALICIOUS — HIGH
treasury-jupiter[.]fun
This domain, treasury-jupiter.fun, poses an elevated risk as a brand impersonation threat targeting users of the Jupiter platform.
- VirusTotal
- 5/95
- Blocklists
- No stored match
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
treasury-jupiter.fun — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Jupiter; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 5/95 (alphaMountain.ai, BitDefender, Fortinet, G-Data, Gridinsoft); PhishDestroy score 65/100. مسجّل النطاق: PDR.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
treasury-jupiter.fun Fake Jupiter Exchange Alert
This domain, treasury-jupiter.fun, poses an elevated risk as a brand impersonation threat targeting users of the Jupiter platform.
This domain, treasury-jupiter.fun, poses an elevated risk as a brand impersonation threat targeting users of the Jupiter platform. Analysis indicates the site was designed to mimic legitimate Jupiter services, likely to deceive visitors into disclosing sensitive credentials, financial details, or installing malicious software. The domain’s infrastructure and content were structured to exploit trust in the Jupiter brand, potentially leading to account takeovers or unauthorized transactions if users engaged with the site. Infrastructure analysis reveals the domain was registered on December 13, 2025, through PDR Ltd. d/b/a PublicDomainRegistry.com. It resolved to the IP address 104.21.77.194 and was flagged by 5 out of 95 security vendors on VirusTotal. The domain appeared on one security blocklist and was included in a single threat intelligence pulse on AlienVault OTX. The page title, 'Just a moment...,' suggests the use of evasion techniques to delay or obscure detection, a common tactic in phishing campaigns. Users who visited treasury-jupiter.fun should take immediate action to mitigate potential risks. Disconnect any devices used to access the site from networks and perform a full antivirus scan to detect malware. Reset passwords for any accounts accessed or credentials entered on the site, prioritizing financial or cryptocurrency-related platforms. Monitor accounts for unauthorized activity and enable multi-factor authentication where available. If financial information was disclosed, contact relevant institutions to report potential fraud and request account reviews. Avoid interacting with any communications linked to the domain, as follow-up attacks may occur.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.