claim[.]humafinance[.]co
claim.humafinance.co — Não verificado. Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 2/91 (CRDF, Gridinsoft); PhishDestroy score 63/100. Registrador: PDR.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
claim.humafinance.co was registered on March 06, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. The domain resolves to the Cloudflare‑owned address 172.67.137.230, which is associated with AS13335 in the United States. The TLS certificate is issued by Let’s Encrypt (E8), and the site presents the generic page title “Just a moment…”. The HTTP response code is 403, indicating that access to the underlying resource is currently denied.
Infrastructure analysis shows the domain is served behind Cloudflare, with Browser Insights, HTTP/3 support, and the authoritative nameservers johnathan.ns.cloudflare.com and sierra.ns.cloudflare.com. Reputation services have assigned a Gridinsoft trust score of 0 out of 100, and the domain appears on a single security blocklist. It is explicitly blocked by PhishDestroy. VirusTotal scans return 0 detections out of 95 engines, which does not imply safety given the other indicators.
The intelligence classification identifies this host as a cryptocurrency‑related “crypto drainer” campaign. The 403 status, combined with the generic page title, suggests a front‑end that may be used to host malicious scripts or to redirect victims after initial credential capture. No public samples or payload hashes have been released, so the exact mechanism for draining cryptocurrency remains unknown. The active flag and the presence on a blocklist indicate ongoing operation.
Defenders should add claim.humafinance.co and its resolving IP 172.67.137.230 to network deny lists and monitor outbound connections for HTTP/3 traffic to Cloudflare edge nodes serving this domain. Continuous re‑scanning on VirusTotal or similar platforms is advised, as detection scores may change. Logging of TLS handshake details and alerting on any attempt to retrieve the “Just a moment…” page can provide early indicators of infection attempts. Given the low trust score and active blocklist status, precautionary blocking is recommended pending further forensic investigation.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo