pvufarmland[.]com
“Para Games”
pvufarmland.com — 内容不可用 (HTTP 502). 诈骗类型:Investment Scam. 证据摘要: VirusTotal 9/95 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); 1 external blocklist match (ScamSniffer); PhishDestroy score 77/100. 注册商: Hosting Concepts.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain pvufarmland.com was registered on September 6, 2024 through Hosting Concepts B.V. d/b/a Registrar.eu and is currently hosted on Cloudflare infrastructure, using the authoritative nameservers archer.ns.cloudflare.com and bella.ns.cloudflare.com. DNS resolution points to IP address 188.114.97.3, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. No SSL/TLS certificate was observed for the host, indicating that the site was served over plain HTTP when it was online. The page title retrieved during the brief capture was “Para Games”, while the classified scam type is an investment scam, suggesting the operator attempted to lure victims with a gaming‑related façade to solicit funds.
Reputation scoring from Gridinsoft assigned a value of 0 out of 100, reflecting an extremely low trust rating. VirusTotal analysis returned nine positive detections out of ninety‑five scanners, confirming that multiple security vendors flagged the domain as malicious. The domain is listed on two public blocklists and has been actively blocked by the PhishDestroy and ScamSniffer filtering services. Although the site is presently taken offline, the underlying infrastructure—recent domain creation, Cloudflare fronting, lack of encryption, and low reputation—matches a pattern commonly observed in fast‑flux investment fraud campaigns.
Uncertainties remain regarding the exact content of the landing page, the data collection mechanisms employed, and whether any credential‑stealing forms were presented, because the site is not currently reachable for inspection. Defenders should add pvufarmland.com and its resolving IP 188.114.97.3 to network deny lists, monitor for re‑registration or new subdomains under the same registrar, and share these indicators with internal and external threat‑intelligence feeds.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告
“@DrakardxAngel_cloaking_bot”
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。