Is raidforums.ru safe or a scam?

raidforums.ru is a clone of the seized RaidForums that hosts sections for distributing stolen databases, stealer logs, ransomware services, and cracked accounts.

High Risk
General Web Risk
Captured page preview of raidforums.ru

At a glance

Antivirus · registration · identity
Antivirus detections
0 flagged
56 harmless · 36 undetected · 0 no result
Domain registration
UnavailableRegistered
UnavailableAt scan time
Operator identity
Claimed Only
Contact details are present but not independently verified
Verified factsSaved with this scan
  1. The captured page visually resembles raidforums.com.
  2. No engine classified the URL as malicious or suspicious in this scan; 56 returned harmless, 36 returned undetected, and 0 returned no usable result.
  3. Operator identity: Claimed Only. Contact details are present but not independently verified
  4. Google Safe Browsing returned no listed threat categories for this address at scan time.
  5. The site presented a valid TLSv1.3 certificate at scan time.

Intelligence

The captured page presents itself as RaidForums with sections explicitly labeled for General Leaks, Ransomware-as-a-service, Marketplace, Cracking, Stealer Logs, Combolists, and Cracked Accounts. Recent post titles reference leaked databases and exploit development, while the site directs visitors to a Telegram channel for updates. These elements match the documented harm mechanisms of hosting stolen data, facilitating ransomware services, and selling cracked credentials.

Evidence Map

Reputation
Observed

Multiple reputation sources returned usable results

Identity
Limited

Contact details are present but not independently verified

Behavior
Concern

Observed page behavior or content contains a risk signal

History
Unavailable

No reliable registration history was saved

Risk Factors
  • 1Impersonates the seized RaidForums brand to host illicit content
  • 2Dedicated sections for ransomware-as-a-service, cracking, and database leaks
  • 3Promotes external Telegram channel for coordination
Positive Signals
  • 1Valid TLSv1.3 certificate presented at scan time
  • 2No antivirus engine flagged the URL as malicious

Site Purpose and Visitor Journey

raidforums.ru displays a forum interface titled RaidForums that mirrors the layout and branding of the original seized site. Visitors encounter navigation links to General Leaks, Ransomware-as-a-service, Marketplace, Cracking, Stealer Logs, Combolists, and Cracked Accounts. The page lists thousands of threads in these categories, with recent posts referencing specific leaked databases and exploit code.

Operator Claims and Contact Details

The page lists a phone number and a Telegram channel link but provides no domain email or postal address. The operator identity remains claimed only, with no independent verification of the listed contact.

Security and Infrastructure Signals

The site serves a valid TLSv1.3 certificate and no antivirus engine flagged the URL as malicious in this scan. The hosting IP shows an abuse-confidence score of 0/100. Despite these clean technical signals, the content and structure directly replicate a known illicit forum.

Observed Risk Indicators

Multiple sections promote the sale and distribution of stolen credentials, combolists, and ransomware services. The site includes temporary advertisements and directs users to an external Telegram channel for coordination, consistent with the documented harm mechanisms.

Website Preview

Captured page preview of raidforums.ru
Visual findings

This site is a clear impersonation of the defunct RaidForums, utilizing its branding to host a platform dedicated to illicit cyber activities and data leaks.

  1. 1Site impersonates a known illicit forum (RaidForums) which was officially seized and shut down
  2. 2Content focuses on high-risk activities including 'Leaks', 'Ransomware-as-a-service', and 'Cracking'
  3. 3Promotes external communication via Telegram for updates
  4. 4Contains suspicious 'Temporary Advertisements' emphasizing 'Active Community' and 'Real Traffic'
  5. 5Latest post titles reference exploit development and database leaks

Web Research

No independently sourced claims were found for this report.

Threat Detection

Antivirus results, browser warnings, isolated page observations, and the threat pattern identified in this report.

Antivirus distribution
Recorded engine classifications, not a blanket clean bill
92 engines
Malicious0
Suspicious0
Harmless56
Undetected36
No result0
Antivirus consensus

Antivirus engine results

Result date Jul 16, 2026
Engine classifications
No malicious or suspicious classifications

This scan saved classifications from an antivirus network of 92 engines. 56 returned harmless and 36 returned undetected; those are different outcomes.

0Malicious0Suspicious56Harmless36Undetected0No result92Engines
Clean
Kaspersky
Undetected
Bitdefender
Harmless
Microsoft
Not queried
ESET-NOD32
Not queried
Avira
Not queried
Sophos
Harmless
Fortinet
Harmless
Google Safebrowsing
Not queried
Emsisoft
Harmless

No malicious or suspicious classifications. 56 engines returned harmless, 36 returned undetected, and 0 returned no usable result. This result is one part of the report and does not prove the site is safe.

Threat pattern
General Web Risk
Threat tags
malwareclone siteData Harvester
Top reasons

Evidence behind this threat profile

3 reasons
  1. 1Impersonates the seized RaidForums brand to host illicit content
  2. 2Dedicated sections for ransomware-as-a-service, cracking, and database leaks
  3. 3Promotes external Telegram channel for coordination
Scam-Type Likelihood

3 of 21 categories showed signals

This profile separates the site's primary threat from other patterns supported by the saved page evidence, public research, and security findings.

Top match: observed
observed
High likelihood
95/100
  • Visual analysis states site impersonates known seized forum raidforums.com
  • Title, branding, and structure match the original RaidForums layout
  • Fingerprint match lists visual-clone-of:raidforums.com
observed
High likelihood
92/100
  • Page sections explicitly titled 'Ransomware-as-a-service', 'Cracking', 'Malware Development', 'Exploit & POCs'
  • Recent posts advertise stealer logs, combolists, cracked accounts, and exploit code
  • Visual analysis confirms content focused on illicit cyber activities and data leaks
possible
Moderate likelihood
49/100
  • Forum requires registration to access leaks and marketplace sections
  • No contact email or postal address visible on page

Technical Details

Identity, domain, infrastructure, and connection facts saved with this scan.

July 21, 2026 at 12:09 PM UTC

Identity

6 facts
Operator
Claimed Only
On-domain email
Not observed
Other email
Not observed
Phone
10 numbers
Postal address
Not observed
Social profiles
1 link

Domain

8 facts
Domain age
Unavailable
Registered
Unavailable
Registrar
Unavailable
Expires
Unavailable
WHOIS updated
Unavailable
Registrant
Unavailable
Registration country
Unavailable
WHOIS privacy
Unavailable

Infrastructure

14 facts
HTTPS
Valid certificate
TLS protocol
TLSv1.3
Certificate issuer
Let's Encrypt · YR2
Certificate subject
raidforums.ru
Certificate valid from
Jul 17, 2026
Certificate valid to
Oct 15, 2026
Network address
185.129.102.34
ASN
Unavailable
Hosting organization
DDOS-GUARD LTD
Country
RU
Server
ddos-guard
Site platform
Unavailable
IP reputation
0% confidence · 0 reports
Tor exit node
No

Connections

13 facts
Scan scope
Domain
Destination host
raidforums.ru
Redirects
1
Cross-domain redirect
No
Redirect status codes
301 → 200
Lookalike characters
Not observed
Internationalized domain
No
Page response
200
Observation coverage
Unavailable
Extracted links
Unavailable
Unique IPs contacted
Unavailable
Countries contacted
Unavailable
Referenced domains
5

What to do

1
Before interacting
Do not visit or register

Do not visit or register. The site hosts sections for distributing stolen databases, stealer logs, ransomware services, and cracked accounts.

2
If you already interacted

If you paid, contact your bank or payment provider immediately and preserve receipts and messages. If you shared personal information, monitor the affected accounts and change any reused passwords through the official service.

Final Verdict

Do not visit or register

Why this verdict

The verdict is malicious because the site impersonates the original RaidForums, offers dedicated sections for ransomware-as-a-service, cracking, combolists, and database leaks, and promotes an external Telegram channel for coordination.

Recommendation

Do not visit or register. The site hosts sections for distributing stolen databases, stealer logs, ransomware services, and cracked accounts.

Key evidence

  1. 1Impersonates the seized RaidForums brand to host illicit content
  2. 2Dedicated sections for ransomware-as-a-service, cracking, and database leaks
  3. 3Promotes external Telegram channel for coordination
Evidence: moderateScope: DomainFresh scan: July 21, 2026 at 12:09 PM UTC

Safety FAQ

Is raidforums.ru safe to use?+

The verdict is malicious because the site impersonates the original RaidForums, offers dedicated sections for ransomware-as-a-service, cracking, combolists, and database leaks, and promotes an external Telegram channel for coordination.

What should I do about raidforums.ru?+

Do not visit or register. The site hosts sections for distributing stolen databases, stealer logs, ransomware services, and cracked accounts.

How old is raidforums.ru?+

A reliable public registration date was not available for raidforums.ru.

What if I already interacted with raidforums.ru?+

If you paid, contact your bank or payment provider immediately and preserve receipts and messages. If you shared personal information, monitor the affected accounts and change any reused passwords through the official service.

When was this report updated?+

This report reflects the scan completed July 21, 2026 at 12:09 PM UTC.