pumamy[.]cheap
“Mall”
Kanıt özeti
The domain pumamy.cheap was registered on March 11, 2026 through Name.com, Inc. and is currently listed as offline. DNS resolution points to the IP address 34.96.206.232, which belongs to AS396982 Google LLC and is geolocated in Hong Kong. The domain uses four Name.com‑provided nameservers (ns4cjp.name.com, ns2cqs.name.com, ns1cnb.name.com, ns3cna.name.com) and presents an SSL certificate issued by Let’s Encrypt (R13). A simple HTTP request returned the page title "Mall," but no further content analysis is available.
The site appears on a single security blocklist and has been explicitly blocked by PhishDestroy. VirusTotal records show that 10 of 94 scanning engines flagged the domain, indicating a moderate level of detection across the security community. The combination of recent registration, Google‑hosted infrastructure, and TLS provisioning suggests a low‑cost, fast‑deployment phishing operation, consistent with the generic phishing classification.
Uncertainty remains regarding the specific payload or credential‑harvesting mechanisms employed, as no page content or URL path details have been disclosed. Defenders should continue to monitor DNS queries for pumamy.cheap, enforce blocklist updates that include the domain, and consider adding the IP address 34.96.206.232 to network‑level deny lists, especially for traffic originating from or destined to Hong Kong. Ongoing collection of threat intel, such as sandbox execution of any retrieved page snapshots, would help clarify the exact malicious behavior and improve detection rules for similar infrastructure.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | pumamy.cheap |
malicious | Sinkholed |
| Hagezi Threat Feed | pumamy.cheap |
malicious | Sinkholed |
| DigiCert UltraDNS | pumamy.cheap |
malicious | Sinkholed |
| DNS4EU | pumamy.cheap |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of pumamy.cheap · checked Mar 25, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin