MALICIOUS — CRITICAL
diamondorpaper[.]fun
3 of 91 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer); the latest stored check returned HTTP 200.
- VirusTotal
- 3/91
- Blocklists
- 1 · ScamSniffer
- Ketersediaan
- Terakhir diketahui aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
diamondorpaper.fun — Terakhir diketahui aktif (HTTP 200). Peniruan identitas merek: Ethereum; Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 74/100.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Digest
diamondorpaper.fun is classified critical with an evidence score of 74/100. 3 of 91 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer). Registered 21 Feb 2026, hosted on 51.254.178.24 (OVH OVH SAS, FR, FR). The latest stored check on 9 Aug 2026 returned HTTP 200 and includes a capture.
Stored generated summary (templated)cerebras · 22/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis indicates that the domain diamondorpaper.fun was created on February 21, 2026. The site displayed a page titled “Diamond or Paper Hands? – Test Your Crypto Resolve” and is classified as a crypto scam that impersonates the Ethereum brand. Independent reputation services rate the domain extremely poorly: Gridinsoft assigned a trust score of 0 out of 100, and Scamadviser reported a score of 1 out of 100, both suggesting a high probability of malicious activity. DNS resolution points to IP address 51.254.178.24, which belongs to ASN 16276 (OVH SAS) and is geolocated in France.
The domain uses three njalla nameservers – 3-get.njalla.in, 1-you.njalla.no, and 2-can.njalla.in – a pattern often seen in disposable or quickly‑re‑hosted malicious infrastructure. An SSL certificate identified only as “E5” is present; the certificate’s low trust rating offers no indication of legitimacy. VirusTotal logged a single positive detection out of 95 scanning engines, confirming that at least one security vendor flagged the domain as malicious. The domain is listed on two public blocklists, PhishDestroy and ScamSniffer, reinforcing its recognition by anti‑phishing communities.
Current probing shows the site is offline, but historical evidence demonstrates it was active after registration. Defenders should block both the domain and its hosting IP at network perimeters, add the domain to internal threat‑intel feeds, and monitor the listed njalla nameservers for any re‑activation. Because the actual page content has not been captured, the specific luring mechanisms and any embedded payloads remain uncertain; security teams should attempt to archive the site if it resurfaces. Ongoing surveillance of the OVH hosting range is recommended, as the provider has been associated with other cryptocurrency‑related fraud campaigns.
Cakupan data13 recorded checks
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Intelijen Forensik
Analisis VirusTotal
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.