fumbi[.]network
“Access Forbidden”
This domain, fumbi.network, is currently flagged as an active cryptocurrency wallet phishing site designed to harvest user credentials and private keys. Analysis indicates the infrastructure is operational, with no confirmed brand impersonation at this stage, though the phishing methodology aligns with common wallet-draining schemes targeting decentralized finance (DeFi) users. The domain remains under investigation for its precise targeting mechanisms and payload delivery methods. Infrastructure analysis reveals the domain was registered on June 11, 2026, through GoDaddy.com, LLC, and resolves to the IP address 37.9.175.187. Despite its active status, the domain has not been flagged by any of the 95 vendors on VirusTotal as of the latest scan, though it appears on one security blocklist. The SSL certificate is issued by Let's Encrypt (R13), a common choice for both legitimate and malicious domains due to its free and automated issuance process. The absence of detections on major scanning platforms contrasts with its blocklist inclusion, suggesting either recent deployment or evasion techniques. The domain remains active and poses an ongoing threat to users who may encounter it through phishing links distributed via email, social media, or compromised advertisements. Users are advised to avoid interaction with fumbi.network and report any associated URLs to security platforms for further analysis. Organizations should update their web filtering rules to block access to 37.9.175.187 and monitor network traffic for connections to this IP. Given the domain's recent registration and low detection rate, heightened scrutiny is recommended for any communications directing users to this site.
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Site Configuration Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive