bloomsniper[.]cfd
“Bloom Sniper”
साक्ष्य सारांश
Analysis of bloomsniper.cfd indicates it was used for a generic phishing campaign and is currently taken offline. The domain was registered on February 23, 2026 through NiceNIC International Group Co., Limited and resolves to the IP address 104.21.26.57, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. DNS resolution is served by the Cloudflare nameservers dalary.ns.cloudflare.com and fonzie.ns.cloudflare.com. The site presented the page title "Bloom Sniper" and employed Tailwind CSS, Cloudflare services, and HTTP/3 for delivery.
An SSL certificate issued by Google Trust Services (WE1) was observed, confirming the use of standard HTTPS encryption. Security scanning on VirusTotal shows that three of ninety‑three antivirus vendors flagged the domain, suggesting malicious activity. The domain appears on a single external blocklist and has been explicitly blocked by PhishDestroy. Independent trust scoring from Gridinsoft assigns a score of 0 out of 100, indicating an extremely low reputation.
Although the site is no longer reachable, the infrastructure fingerprint—Cloudflare‑hosted IP, Tailwind CSS front‑end, and a Google‑issued certificate—matches patterns seen in other phishing operations. Defenders should add 104.21.26.57 to network deny lists, enforce DNS‑level blocking for bloomsniper.cfd, and monitor for newly registered domains that resolve to the same Cloudflare IP range with similar technology stacks. Continuous threat‑intel feeds should be consulted for any resurgence of the domain or its aliases, and endpoint protection solutions should be updated to reflect the three vendor detections reported on VirusTotal.
भेजे गए प्रमाण का स्नैपशॉट
- भेजा गया
- लेज़र रिकॉर्ड
- 1
- केस आईडी
BKF-20260704-11- PDF दस्तावेज़
- PDF प्रमाण
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 13/08/2026
परिणाम के संग्रहीत प्रमाण
परिणाम और टेकडाउन श्रेय
- परिणाम
held- उपलब्धता
unreachable- कारण
registrar_client_hold- कार्रवाईकर्ता
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- तंत्र
client_hold- विश्वसनीयता
- 95%
- पहला अवलोकन
- नवीनतम अवलोकन
अनुमानित अनुपलब्धता
अनुपलब्धता तक का समय: 0 hप्रमाण SHA-256 a20ba08436bc
पहचान समयरेखा
-
उपलब्धता
पहला संग्रहीत मान: DNS निष्क्रिय
f93a11f87e4d -
उपलब्धता
DNS निष्क्रिय → अज्ञात
84e3f9359581 -
उपलब्धता
अज्ञात → DNS निष्क्रिय
4f5c4738d69c -
उपलब्धता
DNS निष्क्रिय → होल्ड पर
c96caa816a1a -
उपलब्धता
होल्ड पर → DNS निष्क्रिय
f52d526b76a1 -
उपलब्धता
DNS निष्क्रिय → अज्ञात
5797b48e8cbc -
उपलब्धता
अज्ञात → होल्ड पर
e5c5c4c1e712 -
उपलब्धता
होल्ड पर → अज्ञात
2dd4b44f2d4b -
उपलब्धता
अज्ञात → DNS निष्क्रिय
6dfe9145995c -
उपलब्धता
DNS निष्क्रिय → होल्ड पर
dad2b8a3a381
सभी दिखाएँ (15)
-
उपलब्धता
होल्ड पर → DNS निष्क्रिय
641ed81dc4d5 -
उपलब्धता
DNS निष्क्रिय → अज्ञात
a1d69da0ca01 -
उपलब्धता
अज्ञात → होल्ड पर
483100743d92 -
उपलब्धता
होल्ड पर → अज्ञात
969c94319fcf -
उपलब्धता
अज्ञात → DNS निष्क्रिय
d0b7046e8c2f -
उपलब्धता
DNS निष्क्रिय → होल्ड पर
160dd159853f -
उपलब्धता
होल्ड पर → DNS निष्क्रिय
ca9ed662b468 -
उपलब्धता
DNS निष्क्रिय → अज्ञात
a05c28842601 -
उपलब्धता
अज्ञात → होल्ड पर
243cd6678445 -
उपलब्धता
होल्ड पर → DNS निष्क्रिय
92f667ff6e00 -
उपलब्धता
DNS निष्क्रिय → अज्ञात
b5802aca5f7c -
उपलब्धता
अज्ञात → होल्ड पर
a097e90f83c9 -
उपलब्धता
होल्ड पर → DNS निष्क्रिय
9eda8dc3b7e8 -
उपलब्धता
DNS निष्क्रिय → अज्ञात
3e7409f0c608 -
उपलब्धता
अज्ञात → होल्ड पर
a20ba08436bc
समुदाय रिपोर्ट
1 समुदाय सदस्य ने रिपोर्ट किया; पहली बार 23/02/2026 को देखा गया
- संग्रहीत रिपोर्ट
- 1
- रिपोर्ट किए गए विशिष्ट URL
- 1
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
SHORTDOT ज़ोन · सार्वजनिक साक्ष्य
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of bloomsniper.cfd · checked Mar 2, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।