pumlp[.]fun
“Pump”
pumlp.fun — Konten tidak tersedia (HTTP 502). Ringkasan bukti: VirusTotal 1 detections (engine total unavailable) (Chong Lua Dao); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: NameSilo.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
On July 24, 2026, analysis of the domain pumlp.fun shows that it was created on March 06, 2026 and is currently taken offline. The site presented a page title of “Pump”, but no SSL certificate was observed during the scan. DNS resolution points to the IP address 104.21.82.114, which belongs to Cloudflare, Inc. (AS13335) and is geolocated to the United States. The domain is registered through NameSilo, LLC and uses the Cloudflare nameservers magdalena.ns.cloudflare.com and rohin.ns.cloudflare.com.
Independent threat‑intelligence feeds have listed pumlp.fun on three blocklists, specifically PhishDestroy, MetaMask, and SEAL, indicating that multiple security vendors have observed malicious activity associated with this host. VirusTotal’s latest scan recorded a single positive detection out of 95 security vendors, reinforcing the suspicion of abuse. No HTTPS certificate was present, which is consistent with the rapid takedown observed for many phishing infrastructure. The available evidence confirms that pumlp.fun functioned as a phishing‑type site, although the exact commodity or credential‑stealing mechanism has not been disclosed beyond the generic “Pump” page title.
Because the domain is presently offline, active exploitation is unlikely, but the underlying hosting infrastructure (Cloudflare) may be reused for future campaigns. Defenders should continue to block the domain at perimeter firewalls and DNS filters, add the associated IP address to threat‑intel watchlists, and monitor for any re‑registration of the same name or similar‑looking domains. Continuous ingestion of blocklist updates from PhishDestroy, MetaMask, and SEAL is recommended to capture potential re‑emergence. Additionally, security teams should verify that internal logs do not contain recent requests to the IP 104.21.82.114, which could indicate lingering activity before the takedown.
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260306-F5AF8A Recipient: abuse@namesilo.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive