huddle01[.]finance
Análisis de phishing y seguridad de huddle01.finance
“Home – Huddle01's Documentation”
huddle01.finance — error del servidor (HTTP 521). Suplantación de marca: Discord; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, Webroot); Spamhaus DBL_PHISH; PhishDestroy score 65/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of huddle01.finance shows a high‑risk brand‑impersonation campaign targeting Discord users. The domain was registered on February 21, 2026 through NiceNIC International Group Co., Limited and is hosted on Cloudflare infrastructure (ASN13335) with the IP address 66.33.60.194 located in the United States. DNS resolution uses the Cloudflare nameservers arnold.ns.cloudflare.com and audrey.ns.cloudflare.com, and the site serves over HTTP/3 with a Google Trust Services / WE1 SSL certificate. An HTTP 521 response indicates that the origin server is unavailable, a pattern often observed in malicious landing pages that rely on Cloudflare’s error handling to obscure content delivery.
The page title returned by the server is "Home – Huddle01's Documentation," which does not reference Discord but may be used to lend an air of legitimacy. Threat intelligence indicates that the domain is actively listed on three security blocklists and has been flagged by PhishDestroy, MetaMask, and SEAL, yet it remains reachable. VirusTotal scans show five of ninety‑one security vendors flagging the domain, and AlienVault OTX references the domain in a single pulse, reinforcing its malicious classification.
The Gridinsoft trust score of 0 out of 100 further underscores the lack of benign reputation. The campaign explicitly impersonates Discord, as indicated by the "Impersonates: discord" tag, suggesting that any phishing pages hosted under this domain likely mimic Discord login flows or notifications to harvest credentials.
Defenders should block the domain at DNS and proxy layers, add the associated IP address to blacklists, and monitor for outbound connections to Cloudflare edge nodes that resolve to 66.33.60.194. Users should be warned that any unsolicited communication referencing Discord that redirects to huddle01.finance is fraudulent.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:43:58 UTC
Tecnologías · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of huddle01.finance · checked Apr 30, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.