MALICIOUS — CRITICAL
Is prime-link.buzz a Crypto Drainer Scam Site?
prime-link[.]
PhishDestroy has identified prime-link.buzz as an active crypto drainer domain designed to steal cryptocurrency from unsuspecting users.
- VirusTotal
- 5/91
- Blocklists
- No stored match
- Disponibilità
- Ultimo attivo conosciuto · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@server-panel.net.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
prime-link.buzz — Ultimo attivo conosciuto (HTTP 200). Tipo di truffa: Crypto Drainer. Riepilogo delle prove: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 80/100. Registrar: NameSilo.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy has identified prime-link.buzz as an active crypto drainer domain designed to steal cryptocurrency from unsuspecting users. The site poses as a legitimate crypto service portal, tricking victims into connecting their wallets and authorizing fraudulent transactions. Once connected, the drainer silently transfers assets to attacker-controlled addresses without requiring additional permissions. Security researchers note that this technique bypasses traditional wallet security by exploiting user trust during the initial authentication phase, making it particularly dangerous for users interacting with decentralized finance platforms. This domain resolves to IP address 45.147.197.100 and currently shows 2/95 detections on VirusTotal, indicating that most antivirus engines have not yet identified its malicious nature. The domain uses a Let's Encrypt SSL certificate to appear legitimate, though this provides no actual security benefit against crypto drainer functionality. The infrastructure shares hosting with other high-risk domains, and the domain was likely registered recently given its minimal detection history. These technical indicators suggest an emerging threat rather than an established campaign, which makes early detection and blocking even more critical. Users who have visited prime-link.buzz should immediately disconnect their wallets from any unauthorized connections and transfer remaining assets to a clean wallet. Check transaction history for any suspicious outbound transfers and report them to your wallet provider immediately. Use browser security extensions that block known malicious domains and consider revoking any wallet connections made while visiting this domain. Maintain constant vigilance when interacting with crypto services, and verify URLs through official channels before entering any wallet information.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ZONA SHORTDOT · PROVE PUBBLICHE
.buzz
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 2 identified
DDoS-Guard is a Russian Internet infrastructure company which provides DDoS protection, content delivery network services, and web hosting services.
ddos-guard.net Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of prime-link.buzz · checked May 15, 2026
Analisi della configurazione del sito
Dati e relazioni esterneIndependent lookups and source reports
PD-20260515-688BCB Recipient: abuse@server-panel.net Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.