claim[.]humafinances[.]network
The domain claim.humafinances.network was registered on November 26, 2025 through PDR Ltd. d/b/a PublicDomainRegistry.com and is currently flagged as a high‑risk crypto drainer. Infrastructure analysis shows the domain is hosted behind Cloudflare, using the nameservers lovisa.ns.cloudflare.com and noel.ns.cloudflare.com. DNS resolution points to IP address 172.67.133.168, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The site serves content over HTTPS with a certificate issued by Google Trust Services under the WE1 intermediate, confirming a valid TLS chain. HTTP traffic is observed on HTTP/3 and returns a 403 status code, while the page title reported by scanners is "Just a moment...".
Threat intelligence platforms have identified the domain on a single security blocklist, and PhishDestroy has already blocked access. VirusTotal analysis records a single positive detection out of 95 security vendors, indicating at least one engine has recognized malicious intent. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the classification as a malicious resource. No additional public references or benign categorizations have been observed.
Defenders should prioritize blocking the domain at network perimeters and endpoint filters, especially those leveraging Cloudflare IP ranges, to prevent inadvertent credential or crypto‑wallet exposure. Continuous monitoring of the associated IP address is advised, as Cloudflare often serves multiple unrelated domains, but the current configuration aligns with known crypto‑drainer infrastructure. Incident response teams should treat any inbound connections to this host as suspicious and consider isolating affected systems. Threat hunters can use the registrar and nameserver data to enrich detection rules and correlate with other campaigns that employ similar Cloudflare front‑ends.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: humafinances.network
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain humafinances.network behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive