pumpmonster[.]fun
Verificação de phishing e segurança de pumpmonster.fun
“pump”
pumpmonster.fun — Conteúdo indisponível (HTTP 502). Tipo de golpe: Crypto Drainer. Resumo das evidências: VirusTotal 2/94 (Gridinsoft); URLQuery 1 alert; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 74/100. Registrador: Dynadot.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies pumpmonster.fun as an active cryptocurrency drainer kit distribution domain, likely targeting unsuspecting users with fake token offers or deceptive airdrops. The site mimics legitimate crypto platforms to siphon funds via malicious JavaScript payloads designed to drain connected wallets. While no specific brand is directly spoofed at this stage, the infrastructure and operational patterns align with known cryptocurrency phishing campaigns leveraging social engineering tactics. The domain’s registration and hosting choices suggest a deliberate attempt to blend into the decentralized web ecosystem, complicating early detection. This domain was flagged during routine threat hunting with a VirusTotal score of 2/95 detections, indicating it remains under the radar of most security vendors. It resolves to IP 193.233.82.208 and is registered through Dynadot Inc, with a creation date of April 18, 2026. The SSL certificate, issued by Let’s Encrypt, adds a veneer of legitimacy, a common tactic to evade browser-based warnings. Google Safe Browsing (GSB) has not yet flagged the domain, and no blocklist entries are currently recorded across major threat intelligence feeds. The recent registration and clean record could indicate a newly deployed threat actor asset poised for rapid deployment in targeted campaigns. As of this advisory, pumpmonster.fun remains active with no active takedown or mitigation in place. SOC teams are advised to immediately add the domain and its resolving IP to network and endpoint blocklists. Users should avoid interacting with the domain and report any related incidents to their security teams. The current risk remains high due to the active status and lack of vendor detections, though attribution and campaign scope are still under investigation. Proactive hunting for related infrastructure and campaign artifacts is strongly recommended to prevent further compromise.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | ipfs.io |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 2 identified
Ubuntu is a free and open-source operating system on Linux for the enterprise server, desktop, cloud, and IoT.
www.ubuntu.com 100% de confiançaApache is a free and open-source cross-platform web server software.
httpd.apache.org 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
PD-1776863016-pumpmonster.fun Recipient: abuse@dynadot.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo