claim[.]humafinance[.]co
claim.humafinance.co — Doğrulanmamış. Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 2/91 (CRDF, Gridinsoft); PhishDestroy score 63/100. Kayıt kuruluşu: PDR.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
claim.humafinance.co was registered on March 06, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. The domain resolves to the Cloudflare‑owned address 172.67.137.230, which is associated with AS13335 in the United States. The TLS certificate is issued by Let’s Encrypt (E8), and the site presents the generic page title “Just a moment…”. The HTTP response code is 403, indicating that access to the underlying resource is currently denied.
Infrastructure analysis shows the domain is served behind Cloudflare, with Browser Insights, HTTP/3 support, and the authoritative nameservers johnathan.ns.cloudflare.com and sierra.ns.cloudflare.com. Reputation services have assigned a Gridinsoft trust score of 0 out of 100, and the domain appears on a single security blocklist. It is explicitly blocked by PhishDestroy. VirusTotal scans return 0 detections out of 95 engines, which does not imply safety given the other indicators.
The intelligence classification identifies this host as a cryptocurrency‑related “crypto drainer” campaign. The 403 status, combined with the generic page title, suggests a front‑end that may be used to host malicious scripts or to redirect victims after initial credential capture. No public samples or payload hashes have been released, so the exact mechanism for draining cryptocurrency remains unknown. The active flag and the presence on a blocklist indicate ongoing operation.
Defenders should add claim.humafinance.co and its resolving IP 172.67.137.230 to network deny lists and monitor outbound connections for HTTP/3 traffic to Cloudflare edge nodes serving this domain. Continuous re‑scanning on VirusTotal or similar platforms is advised, as detection scores may change. Logging of TLS handshake details and alerting on any attempt to retrieve the “Just a moment…” page can provide early indicators of infection attempts. Given the low trust score and active blocklist status, precautionary blocking is recommended pending further forensic investigation.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin