s2-jup[.]live
Riepilogo delle prove
Analysis of s2-jup.live shows that the domain is presently offline but was previously serving a page titled “Just a moment…”. The site was hosted on Cloudflare’s network, resolving to IP 172.67.215.249, which belongs to AS13335 Cloudflare, Inc. in the United States. Nameserver records list carlos.ns.cloudflare.com and paloma.ns.cloudflare.com, confirming the use of Cloudflare’s DNS services. No TLS certificate was observed, indicating that the site operated without HTTPS protection. Threat intelligence flags the domain as a crypto‑related scam that impersonates the brand Jupiter.
The impersonation is reflected in the “Brand target” field and aligns with the “Scam type” designation of Crypto Scam. No additional content analysis is available; the page title is the only visible indicator, and the site’s HTML was not captured. VirusTotal scans returned seven positive detections out of ninety‑five participating vendors, demonstrating a moderate level of consensus among security products that the domain is malicious. The domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy service. Gridinsoft assigned a trust score of 0 out of 100, reinforcing the classification of the site as highly untrustworthy.
Registration data shows the domain was provisioned through Cloudflare, Inc., a common registrar for fast‑deployment infrastructure. The lack of an SSL certificate, combined with the low trust score and multiple vendor detections, suggests the operator prioritized rapid creation over credential protection. Uncertainty remains regarding the exact payload or phishing workflow because no page content or redirect paths were captured before the takedown. Defenders should continue to block the domain at network perimeter devices, update URL filtering lists with the observed IP address and nameserver information, and monitor for any re‑registration attempts that reuse the same brand‑related keywords.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Informazioni forensi
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo