Lompat ke laporan keamanan
Checked 09/08/2026 Ref 9350BD71

MALICIOUS — CRITICAL

diamondorpaper[.]fun

3 of 91 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer); the latest stored check returned HTTP 200.

74/100 evidence score · Critical
VirusTotal
3/91
Blocklists
1 · ScamSniffer
Ketersediaan
Terakhir diketahui aktif · HTTP 200
2026-02-26 22:24 UTCTerakhir diketahui aktif · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Domain ini telah ditandai sebagai berbahaya
Mesin keamanan melaporkan deteksi: 3. Daftar blokir publik yang melaporkan kecocokan: 1. Berhati-hatilah — jangan memasukkan kredensial atau informasi pribadi.
Jump to section
Ringkasan laporan

diamondorpaper.fun — Terakhir diketahui aktif (HTTP 200). Peniruan identitas merek: Ethereum; Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 74/100.

Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.

Evidence Digest

Ref 9350BD71

diamondorpaper.fun is classified critical with an evidence score of 74/100. 3 of 91 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer). Registered 21 Feb 2026, hosted on 51.254.178.24 (OVH OVH SAS, FR, FR). The latest stored check on 9 Aug 2026 returned HTTP 200 and includes a capture.

Stored generated summary (templated)cerebras · 22/07/2026

Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.

Analysis indicates that the domain diamondorpaper.fun was created on February 21, 2026. The site displayed a page titled “Diamond or Paper Hands? – Test Your Crypto Resolve” and is classified as a crypto scam that impersonates the Ethereum brand. Independent reputation services rate the domain extremely poorly: Gridinsoft assigned a trust score of 0 out of 100, and Scamadviser reported a score of 1 out of 100, both suggesting a high probability of malicious activity. DNS resolution points to IP address 51.254.178.24, which belongs to ASN 16276 (OVH SAS) and is geolocated in France.

The domain uses three njalla nameservers – 3-get.njalla.in, 1-you.njalla.no, and 2-can.njalla.in – a pattern often seen in disposable or quickly‑re‑hosted malicious infrastructure. An SSL certificate identified only as “E5” is present; the certificate’s low trust rating offers no indication of legitimacy. VirusTotal logged a single positive detection out of 95 scanning engines, confirming that at least one security vendor flagged the domain as malicious. The domain is listed on two public blocklists, PhishDestroy and ScamSniffer, reinforcing its recognition by anti‑phishing communities.

Current probing shows the site is offline, but historical evidence demonstrates it was active after registration. Defenders should block both the domain and its hosting IP at network perimeters, add the domain to internal threat‑intel feeds, and monitor the listed njalla nameservers for any re‑activation. Because the actual page content has not been captured, the specific luring mechanisms and any embedded payloads remain uncertain; security teams should attempt to archive the site if it resurfaces. Ongoing surveillance of the OVH hosting range is recommended, as the provider has been associated with other cryptocurrency‑related fraud campaigns.

VirusTotal
VirusTotal
3 det.
URLScan
URLScan
ScamAdviser
Scamadviser
1/100
Sertifikat TLS
Kedaluwarsa atau belum diverifikasi
Usia
6 mo
Status terpantau
Terakhir diketahui aktif 200
PhishDestroy
Daftar Hapus
Terdaftar
Cakupan data13 recorded checks
VirusTotal 3 / 91 URLQuery laporan disimpan — putusan terperinci menunggu keputusan PhishStats tidak diperiksa OTX no community references CF Radar no data URLScan capture laporan yang disimpan URLScan verdict Analisis selesai Pemblokiran DNS tidak diperiksa TLS Kedaluwarsa atau belum diverifikasi WHOIS 6 mo old Tangkapan layar 2 captures · 2 sources Rantai pengalihan tidak diselidiki Scamadviser 1/100

Alur Tanggapan Ancaman Pipeline

Penemuan
Checks
Reports
Ketersediaan
10/12

Status Daftar Blokir Publik

Tangkapan tersimpan

Intelijen Domain

Domain
URLScan Verdict Analisis selesai score 0 report ↗
Server / ASN nginx/1.18.0 (Ubuntu) · AS16276 OVH OVH SAS, FR
Reputasi IP abuse score 0/100 0 reports checked 31/07/2026
Alamat IP 51.254.178.24 FR
LokasiFR Lille, FR
JaringanAS16276 · OVH SAS
PendaftaranDibuat 21/02/2026 (169d)
Elapsed Since First Report 54 days
Yang kami hitung Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Terakhir diketahui aktif.
Isi setiap laporan Catatan laporan keluar yang disimpan dapat merujuk pada bukti yang tersedia pada saat itu, seperti keputusan vendor, data pendaftaran, detail hosting, klasifikasi, atau tangkapan layar. Halaman ini tidak menyimpulkan secara pasti muatan yang dikirimkan, penerimaan, pengakuan, atau tindakan oleh penerima.
Status HTTP200
Rincian teknisDNS, SAN SSL, cap waktu
Pertama Kali Terdeteksi26/02/2026
DOM Analysisanalyzed 24/03/2026score 56/1002 brand signals
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Server nama2-can.njalla.in
Judul Halaman
Diamond or Paper Hands? - Test Your Crypto Resolve
Impersonates
Ethereum Solana
Sertifikat TLS
Kedaluwarsa atau belum diverifikasi · Diterbitkan oleh E5

Intelijen Forensik

External Scripts 1
https://performance.radar.cloudflare.com/beacon.js
Laporkan Domain Ini Kirimkan bukti & bantu lindungi orang lain

Analisis VirusTotal

3 / Vendor keamanan 91 menandai domain ini
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
alphaMountain.ai
CRDF
Gridinsoft
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.

Europol
Temukan saluran pelaporan resmi untuk negara UE Anda
National police directory
Waspadalah terhadap penipu yang mengatasnamakan pemulihan! Penjahat dapat menghubungi korban lagi sambil berpura-pura menjadi penyelidik, pengacara, atau agen pemulihan. Jangan membayar biaya di muka atau membagikan kredensial. Pelajari lebih lanjut tentang penipuan dalam proses pemulihan →

Laporkan kepada Pihak Berwenang di Daerah Anda

Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.

Direktori 97 negara
Draf yang dibantu AI — detail insiden diproses oleh penyedia AI Tinjau dan kirimkan sendiri
Sematkan Laporan IniRead-only HTML widget
HTML · IFRAME

Sematkan Laporan Ini

Bagikan informasi ancaman ini di situs web atau blog Anda

embed.html
<iframe
  src="https://phishdestroy.io/id/embed/domain/diamondorpaper.fun"
  title="PhishDestroy threat report for diamondorpaper.fun"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>