pudgy-claim[.]app
“Claim Your $PENGU | Pudgy Penguins”
pudgy-claim.app — Ошибка сервера (HTTP 502). Олицетворение бренда: Ethereum; Тип мошенничества: Fake Airdrop. Сводка доказательств: VirusTotal 16/94 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar); URLQuery 1 alert; Spamhaus DBL_PHISH; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 95/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain pudgy-claim.app was registered on 24 March 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and immediately pointed to the Cloudflare network (nameservers doug.ns.cloudflare.com and rachel.ns.cloudflare.com). DNS resolution returns the address 104.21.41.175, which is associated with Cloudflare, Inc. and geolocated to Canada. The site served a page titled "Claim Your $PENGU | Pudgy Penguins", indicating a fake airdrop targeting holders of the Pudgy Penguins token. Technical analysis shows the site employed HSTS, Cloudflare Browser Insights, and HTTP/3, but did not present a valid SSL certificate, which is inconsistent with typical Cloudflare deployments and may reflect a misconfiguration or rapid takedown.
Multiple security platforms have flagged the domain: PhishDestroy, MetaMask, ScamSniffer, and SEAL list it as malicious, and VirusTotal recorded 16 of 94 scanning engines marking it as suspicious. The domain appears on four external blocklists, and Gridinsoft assigned a trust score of zero out of one hundred, reinforcing the assessment of high risk. The service was taken offline before the report date, but the infrastructure components remain observable.
Uncertainty remains regarding the exact phishing kit or backend infrastructure used to capture private keys, as no further artifact analysis is available. Defenders should continue to block the domain at network perimeter, update endpoint and browser protection signatures, and monitor for any re‑registration attempts or similar airdrop‑style lures referencing $PENGU or Pudgy Penguins. Additional forensic capture of the page content, if restored, would aid in attributing the operators and refining detection rules.
Данные сетевой безопасности Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | claim.pudgypenguins.com |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-17 03:15:17 UTC
Технологии · 4 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of pudgy-claim.app · checked Mar 24, 2026
Доказательства и внешние отчеты
PD-20260324-73EF8C Recipient: abuse@nicenic.net, registrar-abuse@google.com, compliance@icann.org Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание