# PhishDestroy threat dossier — pump-streamer.fun ================================================================ Fetched: 2026-05-08 15:59:40 UTC Canonical: https://phishdestroy.io/domain/pump-streamer.fun/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 2/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.14.224 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com Nameservers: lynn.ns.cloudflare.com, walk.ns.cloudflare.com Registered: 2026-05-04 Page title: Pump HTTP response: 530 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-08-02 Status: INVALID chain Fingerprint: 98e4fc8dde6f677bf9e244671856838ddc1f1af3af5f3f92f60545d1c96777c1 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-04 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-07 02:02:50 UTC (by PhishDestroy tracker) First reported: 2026-05-06 23:08:34 UTC (abuse notice filed) Last verified: 2026-05-08 16:37:24 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dff86-1da0-71db-a3d8-24c9d3aa31b8/ URLQuery: https://urlquery.net/report/e2fcc295-e63e-4b64-81d9-6245c57fe0fa Wayback Machine: https://web.archive.org/web/*/pump-streamer.fun crt.sh CT logs: https://crt.sh/?q=%25.pump-streamer.fun Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=pump-streamer.fun AlienVault OTX: https://otx.alienvault.com/indicator/domain/pump-streamer.fun URLhaus: https://urlhaus.abuse.ch/host/pump-streamer.fun/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-07 02:04:53 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies pump-streamer.fun as a generic phishing domain currently under active investigation. This domain poses a generic phishing threat targeting unsuspecting users via deceptive tactics to harvest sensitive credentials or financial data. As of the latest assessment, pump-streamer.fun remains unflagged by the security community, registering 0 detections out of 95 VirusTotal vendors. The domain was registered through PDR Ltd. d/b/a PublicDomainRegistry.com, resolves to IP 104.21.14.224, and holds a valid Let’s Encrypt SSL certificate issued post-domain creation. Notably, the domain was created on May 04, 2026—suggesting it is a recently deployed resource with minimal observed history. PhishDestroy assesses the risk profile of pump-streamer.fun as under_investigation due to its fresh registration, low detection coverage, and apparently legitimate infrastructure (e.g., valid SSL). While no blocklist count or trust scores were provided, the combination of a new domain, generic naming, and hosting infrastructure warrants heightened caution. At present, there are no confirmed reports of brand impersonation or specific lure content, but the domain’s rapid deployment and clean initial reputation suggest it is being prepared for malicious campaigns. PhishDestroy recommends that end users avoid interacting with pump-streamer.fun and treat any communications referencing the domain with extreme skepticism. Security teams should block inbound and outbound connections to IP 104.21.14.224 and monitor for associated domains registered through PDR Ltd. Immediate reporting to domain registries and threat intelligence platforms is advised to accelerate vendor detection updates. Until further intelligence emerges, this domain should be considered a potential phishing vector with evolving risk. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260506-7960F3 Favicon MD5: 3b95f264ba9ca3874a7cd5528ce97142 TLS cert SHA-256: 98e4fc8dde6f677bf9e244671856838ddc1f1af3af5f3f92f60545d1c96777c1 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/pump-streamer.fun/ JSON API: https://api.destroy.tools/v1/check?domain=pump-streamer.fun Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 147,303 domains (48,255 alive under monitoring, 98,778 confirmed takedowns/dead). Site: https://phishdestroy.io