claims-puffer[.]live
“Nur einen Moment…”
claims-puffer.live — Konten tidak tersedia. Peniruan identitas merek: Puffer; Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 6/95 (alphaMountain.ai, BitDefender, CyRadar, Fortinet, G-Data); PhishDestroy score 68/100. Registrar: NameSilo.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, claims-puffer.live, was observed hosting a page whose HTML title resolved to “Nur einen Moment…”. The site was registered through NameSilo, LLC and was served from the Cloudflare network (AS13335) with the origin IP address 188.114.97.3 located in the United States. DNS resolution used the Cloudflare authoritative nameservers julissa.ns.cloudflare.com and nick.ns.cloudflare.com. No TLS certificate was presented, indicating the site operated over plain HTTP. The page was classified as a crypto‑scam that impersonates the brand “puffer”.
The domain has been listed on one security blocklist and was actively blocked by PhishDestroy. VirusTotal analysis recorded six detections out of ninety‑five scanners, confirming malicious intent. As of the report date, the domain is taken offline, and no further HTTP response can be retrieved. The available evidence confirms that the infrastructure leveraged Cloudflare’s edge network, a common tactic to hide origin servers and benefit from the provider’s global CDN. However, the lack of a certificate and the simple page title provide limited visibility into the exact payload or user‑interaction flow.
Defenders should continue to monitor the IP address 188.114.97.3 for any re‑use, enforce outbound filtering to block connections to this host, and add the domain to internal blocklists. Correlation with other Cloudflare‑hosted malicious domains may reveal shared command‑and‑control infrastructure. Because the site is currently offline, any ongoing campaigns must rely on previously distributed links; threat‑hunting teams should search for email or messaging artifacts that reference the URL or the “Nur einen Moment…” title. Additional investigation of the six VirusTotal detections can provide indicator‑of‑compromise (IOC) hashes or URLs that were fetched during the scan, further enriching detection rules.
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Intelijen Forensik
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive