pixelweb[.]buzz
“The Official Trump Meme | GetTrumpMemes”
证据摘要
pixelweb.buzz was registered on 21 February 2026 through Web Commerce Communications Limited. The domain resolves to 104.21.73.196, an address owned by Cloudflare, Inc. (AS13335) and geographically attributed to the United States. Authoritative nameservers listed for the zone are louis.ns.cloudflare.com and raegan.ns.cloudflare.com. No TLS certificate is presented, indicating the site is served over plain HTTP. The landing page title recorded by automated crawlers is “The Official Trump Meme | GetTrumpMemes”, which does not reference the targeted brand.
Nevertheless, the intelligence feed classifies the campaign as an Apple‑related wallet/seed phishing operation, suggesting that the underlying content is intended to harvest cryptocurrency recovery phrases while masquerading as an Apple service. The domain is currently offline, and the threat‑level assessment assigns an elevated risk rating. Detection data show that seven of ninety‑three VirusTotal scanners flagged the domain as malicious. Gridinsoft assigns a trust score of zero out of one hundred, and the domain appears on a single external blocklist. PhishDestroy has actively blocked the host.
The combination of a zero trust score, multiple vendor detections, and inclusion on a phishing blocklist confirms the malicious intent despite the lack of a valid SSL certificate. Open questions remain regarding the exact phishing payload, user‑experience flow, and any additional infrastructure such as command‑and‑control servers, because the page content has not been publicly disclosed. Analysts should continue to monitor the domain for any re‑registration or changes in hosting, enforce blocklist rules for the IP address 104.21.73.196, and ensure that endpoint protection solutions flag any connections to this host. Organizations that rely on Apple services should educate users about unsolicited requests for wallet seeds and recommend verification of URLs before entering sensitive credentials.
已提交证据快照
- 已发送
- 台账记录
- 1
- 案件 ID
PD-20260124-B10E12- 已捕获页面标题
- The Official Trump Meme | GetTrumpMemes
- PDF 文件
- PDF 证据
完整证据文本
Policy Violations: Registration Policy + AUP prohibit unlawful use including phishing, spam abuse, malware; registrar can revoke domains
Applicable Laws: Malaysia Computer Crimes Act 1997; BVI fraud laws derived from English common law
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
SHORTDOT 域名区 · 公开证据
.buzz
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控