valorfun[.]xyz
“Night Market”
Ringkasan bukti
On July 24, 2026, the domain valorfun.xyz was observed hosting a page titled “Night Market”. The site is currently offline and has been flagged by the PhishDestroy sinkhole. Registration data indicates that the domain was created on February 21, 2026 through NiceNIC International Group Co., Limited, and it is delegated to Cloudflare name servers doug.ns.cloudflare.com and ollie.ns.cloudflare.com. DNS resolution points to IP address 172.67.129.51, which belongs to AS13335 Cloudflare, Inc., locating the infrastructure in the United States. VirusTotal scans show that five of ninety‑three security vendors flagged the domain, and the domain appears on one public blocklist.
No TLS certificate was presented, confirming the absence of HTTPS encryption at the time of analysis. Automated reconnaissance detected the use of Cloudflare Browser Insights, the Cloudflare CDN, and HTTP/3 protocol, consistent with a typical Cloudflare‑protected staging of malicious content. The Gridinsoft trust score is 0 out of 100, indicating a high confidence of malicious intent. The precise phishing campaign content and any targeted brand or credential‑harvesting form have not been disclosed; the only visible artifact is the page title “Night Market”, which does not directly reveal the intended victim. Consequently, attribution to a specific brand or service remains unknown.
Defenders should add valorfun.xyz to domain blocklists, enforce DNS sinkholing, and monitor outgoing connections to the associated Cloudflare IP range. Organizations using web filtering should ensure the domain is denied, and incident response teams should inspect logs for any recent requests to the IP address or name servers. Because the site employed Cloudflare, threat hunters may also query Cloudflare logs for related subdomains or similar timestamped activity. Continuous re‑scanning on VirusTotal or similar platforms is recommended to capture any future changes in detection status.
Snapshot bukti yang dikirim
- Dikirim
- Catatan buku besar
- 1
- ID kasus
PD-20260218-1A33FA- Judul halaman yang direkam
- Night Market
- Artefak PDF
- Bukti PDF
Teks bukti lengkap
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 13/08/2026
Linimasa deteksi
-
VirusTotal
5 → 6
-
Status domain
Dapat dijangkau → Tidak dapat dijangkau
Tangkapan tersimpan
Intelijen Domain
Detail teknisDNS, nama TLS, dan stempel waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of valorfun.xyz · checked Mar 2, 2026
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive