purple-pepe[.]com
“Home | $PURPE | Purple Pepe”
purple-pepe.com — सर्वर त्रुटि (HTTP 502). ब्रांड प्रतिरूपण: Base; घोटाले का प्रकार: Wallet/seed Phishing. साक्ष्य सारांश: VirusTotal 11/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); 1 external blocklist match (ScamSniffer); PhishDestroy score 83/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain purple-pepe.com was registered on October 03, 2025 through NiceNIC International Group Co., Limited and is currently resolved to the IP address 188.114.97.3, which belongs to AS13335 Cloudflare, Inc. in the United States. The authoritative name servers are dimitris.ns.cloudflare.com and raquel.ns.cloudflare.com, both hosted by Cloudflare. No TLS certificate was observed for the site, indicating that HTTPS was not configured when the domain was active. The page title retrieved from the live endpoint reads "Home | $PURPE | Purple Pepe," which aligns with the reported scam type of Wallet/Seed Phishing.
The domain is explicitly flagged by the Gridinsoft trust scoring system with a score of 0 / 100, and it is listed on two public blocklists that are referenced by PhishDestroy and ScamSniffer. VirusTotal analysis shows that 11 of 95 security vendors reported the domain as malicious, reinforcing the suspicion of malicious activity. Additionally, AlienVault OTX records the domain in a single threat‑intelligence pulse, providing further attribution to the observed campaign. The overall risk assessment is elevated, and the domain has been taken offline at the time of this report.
Defenders should continue to block the domain at perimeter and DNS layers, monitor for any resurgence of the host IP or associated Cloudflare name‑servers, and consider adding the domain to internal blocklists. Given the lack of TLS, the presence of a zero trust score, and multiple vendor detections, the evidence strongly supports a credential‑harvesting operation targeting cryptocurrency wallets. The primary uncertainty is the current activity surface, as the site is offline; however, the historical indicators remain valid for proactive defensive measures.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 03:22:53 UTC
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।