claims-puffer[.]live
“Nur einen Moment…”
claims-puffer.live — Контент недоступен. Олицетворение бренда: Puffer; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 6/95 (alphaMountain.ai, BitDefender, CyRadar, Fortinet, G-Data); PhishDestroy score 68/100. Регистратор: NameSilo.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, claims-puffer.live, was observed hosting a page whose HTML title resolved to “Nur einen Moment…”. The site was registered through NameSilo, LLC and was served from the Cloudflare network (AS13335) with the origin IP address 188.114.97.3 located in the United States. DNS resolution used the Cloudflare authoritative nameservers julissa.ns.cloudflare.com and nick.ns.cloudflare.com. No TLS certificate was presented, indicating the site operated over plain HTTP. The page was classified as a crypto‑scam that impersonates the brand “puffer”.
The domain has been listed on one security blocklist and was actively blocked by PhishDestroy. VirusTotal analysis recorded six detections out of ninety‑five scanners, confirming malicious intent. As of the report date, the domain is taken offline, and no further HTTP response can be retrieved. The available evidence confirms that the infrastructure leveraged Cloudflare’s edge network, a common tactic to hide origin servers and benefit from the provider’s global CDN. However, the lack of a certificate and the simple page title provide limited visibility into the exact payload or user‑interaction flow.
Defenders should continue to monitor the IP address 188.114.97.3 for any re‑use, enforce outbound filtering to block connections to this host, and add the domain to internal blocklists. Correlation with other Cloudflare‑hosted malicious domains may reveal shared command‑and‑control infrastructure. Because the site is currently offline, any ongoing campaigns must rely on previously distributed links; threat‑hunting teams should search for email or messaging artifacts that reference the URL or the “Nur einen Moment…” title. Additional investigation of the six VirusTotal detections can provide indicator‑of‑compromise (IOC) hashes or URLs that were fetched during the scan, further enriching detection rules.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание