puup[.]fun
“Pump”
This domain, puup.fun, is identified as a crypto drainer phishing site designed to compromise digital wallet credentials and siphon cryptocurrency assets. Analysis indicates the site employs deceptive transaction prompts, mimicking legitimate wallet interfaces to trick users into authorizing malicious transfers. The infrastructure is engineered to exploit vulnerabilities in wallet connectivity protocols, enabling unauthorized asset drainage upon interaction. Evidence supporting this assessment includes detection by 16 out of 95 security vendors on VirusTotal, alongside listings on four distinct security blocklists. The domain was registered through Dynadot Inc on March 02, 2026, an unusually future-dated creation that aligns with patterns observed in disposable phishing infrastructure. Hosting is provisioned via Amazon Web Services, with content delivery facilitated by Vercel and jsDelivr, a combination frequently leveraged to obscure malicious payloads. The site resolves to the IP address 188.114.96.3, a host previously associated with transient phishing campaigns. Users who visited puup.fun or interacted with its content should immediately revoke any active wallet authorizations linked to the domain. Disconnect all connected applications from affected wallets and conduct a thorough review of transaction histories for unauthorized activity. If assets were transferred, report the incident to relevant blockchain explorers and law enforcement cybercrime units. Reset credentials for any accounts accessed during the suspected compromise and monitor for anomalous behavior across linked services. Given the high-risk classification, assume all interactions with this domain may have exposed sensitive authentication tokens or private keys.
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
10 个来源 · 于 2026年8月10日 同步
检测时间线
按时间顺序显示已存储的观测记录。
-
VirusTotal
VirusTotal:0 → 5
-
VirusTotal
VirusTotal:5 → 16
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控