mamonthunters[.]network
“404 Not Found”
Analysis of mamonthunters.network indicates that the domain is currently offline but was previously identified as a phishing vector. The site returned a HTTP 404 Not Found page title, and no SSL certificate was observed, suggesting the host did not serve encrypted traffic. The domain resolves to 188.114.97.3, an address owned by AS13335 Cloudflare, Inc., located in the United States. Registration was performed through Cloudflare, Inc., and the authoritative name servers are linda.ns.cloudflare.com and sullivan.ns.cloudflare.com.
Reputation checks show a Gridinsoft trust score of 0 out of 100, and the domain appears on a single security blocklist, where it is listed as blocked by PhishDestroy. VirusTotal analysis reports that two of ninety‑five scanned security vendors flagged the domain, reinforcing the malicious classification. The combination of a low trust score, blocklist inclusion, and multiple vendor detections aligns with the generic phishing categorization supplied in the threat intelligence.
Because the site is presently taken offline, active exploitation may be halted, but the underlying infrastructure—namely the Cloudflare‑protected IP address—remains reusable for future campaigns. Defenders should continue to block the domain and its resolved IP at perimeter devices, monitor DNS queries for the associated name servers, and consider adding the host to internal blocklists. Ongoing observation of the IP address for new domain registrations is advisable, as the same Cloudflare edge could be leveraged for other malicious payloads.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive