aurumfoundation[.]app
“Verification Portal”
Зведення доказів
On July 27, 2026 the domain aurumfoundation.app was registered through Namecheap Inc. The domain is currently active and resolves to the IPv4 address 34.111.179.208. DNS resolution is served by dns1.registrar-servers.com and dns2.registrar-servers.com. Analysis of the hosting environment shows the site runs on Google Cloud infrastructure, employing Node.js with the Express framework, and is delivered via Google Cloud CDN with HTTP/3 support. Transport security is enforced through HTTP Strict Transport Security (HSTS).
The domain has been flagged by one of ninety‑one security vendors on VirusTotal, indicating a single detection of malicious activity. It is also listed on a security blocklist and has been actively blocked by the PhishDestroy filtering service. No additional public threat‑intel sources (e.g., OTX, Safe Browsing) are referenced in the available data, and no page‑title or brand information has been disclosed, leaving the exact phishing lure undefined. The limited detection footprint—one vendor flag and a single blocklist entry—suggests the campaign may be in an early deployment stage or using a low‑profile hosting configuration to evade broader detection.
Defenders should add aurumfoundation.app to outbound‑traffic monitoring rules, enforce DNS sinkholing where possible, and ensure that any credential‑capture attempts targeting the domain are logged and investigated. Continuous re‑scanning on multi‑vendor platforms is recommended to capture any future detections, and threat‑intel feeds should be updated to reflect the domain’s presence on blocklists. Given the active status, the combination of Node.js/Express on Google Cloud and the presence of HSTS indicates a modern web stack that may be used to host credential‑harvesting pages, reinforcing the need for vigilant network‑level controls.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260804-58BC71- Заголовок збереженої сторінки
- Verification Portal
- PDF-файл
- PDF із доказами
Правова підстава
Повний текст доказів
Policy Violations: Domain Registration Agreement prohibits hacking, misuse of domain to conduct attacks, scam and fraudulent activities; AUP allows immediate suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 10.08.2026
9 зовнішніх джерел під наглядом Збігів немає
Хронологія виявлення
-
Перший запис
Перше збережене значення: Доступний
-
Статус домену
Доступний → Недоступний
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 6 технологій із високою впевненістю
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of aurumfoundation.app · checked Aug 4, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога