cashbackterminal[.]gg
“Pump.fun x Padre Cashback - Get Up to 30% Back on Your Losses”
Riepilogo delle prove
This report analyzes the domain cashbackterminal.gg, which presents itself as a fraudulent cryptocurrency scheme. The page title claims to offer "Pump.fun x Padre Cashback - Get Up to 30% Back on Your Losses," directly impersonating the legitimate Pump.fun brand. The primary threat is a cryptocurrency scam designed to deceive users into depositing funds under the false promise of cashback on losses, resulting in financial loss.
Technical evidence confirms the site's malicious nature. VirusTotal detected 3 out of 95 security vendors flagging the domain, with specific alerts from Gridinsoft, Seclookup, and SOCRadar. The domain is hosted on IP address 104.21.89.124 in the United States, assigned to AS13335 Cloudflare, Inc. It was registered on 2026-03-04 through the registrar NETIM. The SSL certificate is rated E7, and nameservers are elias.ns.cloudflare.com and kim.ns.cloudflare.com. The domain appears on 2 blocklists.
The site is currently down or offline. The domain risk score is 56, indicating a high risk of malicious activity. Based on the impersonation of a known brand, low detection rate, and recent creation date, this domain poses a significant threat and should be avoided.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | link-modal-7425.vercel.app/demo.php?id=69afcbf5d52f72e0618b388f&parent_url=cashbackterminal.gg%2f |
audit | Hunting_JS_WebAssembly |
| Nextron YARA rules | pub-14c1504681d2427684ac1f489338d075.r2.dev/phantom-bypass2-desktop.gif |
malware | Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type |
| Nextron YARA rules | pub-14c1504681d2427684ac1f489338d075.r2.dev/solflare-bypass1-desktop.gif |
malware | Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type |
| Nextron YARA rules | pub-14c1504681d2427684ac1f489338d075.r2.dev/solflare-bypass2-desktop.gif |
malware | Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type |
| Nextron YARA rules | pub-14c1504681d2427684ac1f489338d075.r2.dev/solflare-bypass2-mobile.gif |
malware | Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type |
| Nextron YARA rules | pub-14c1504681d2427684ac1f489338d075.r2.dev/phantom-bypass1-desktop.gif |
malware | Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type |
| Nextron YARA rules | pub-14c1504681d2427684ac1f489338d075.r2.dev/solflare-bypass1-mobile.gif |
malware | Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type |
| Nextron YARA rules | pub-14c1504681d2427684ac1f489338d075.r2.dev/phantom-bypass2-mobile.gif |
malware | Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type |
| Nextron YARA rules | pub-14c1504681d2427684ac1f489338d075.r2.dev/phantom-bypass1-mobile.gif |
malware | Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type |
| DigiCert UltraDNS | cashbackterminal.gg |
malicious | Sinkholed |
| DNS4EU | cashbackterminal.gg |
malicious | Sinkholed |
| DigiCert UltraDNS | cloudflare-dns.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
9 fonti esterne monitorate Nessuna corrispondenza
Tecnologie
3 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of cashbackterminal.gg · checked Mar 15, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo