reclaimwise[.]finance
“The 95% Project — Reclaim what fraud took from you”
ملخص الأدلة
reclaimwise.finance is an active crypto‑drainer site observed since its registration on 24 May 2026. The domain resolves to 185.158.133.1, a server located in Frankfurt, Germany, and serves content over HTTPS using a Google Trust Services/WE1 certificate. DNS is delegated to four name servers (ns3fqs.name.com, ns1hwy.name.com, ns2fln.name.com, ns4jnz.name.com) registered through Name.com, Inc. HTTP requests return status 200 and the page title “The 95% Project — Reclaim what fraud took from you”. The site is listed on three security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal analysis shows a single detection out of 91 scanners, and Gridinsoft assigns a trust score of 0 / 100, reinforcing the malicious assessment. Infrastructure indicators, including the German IP address and recent domain age, are consistent with fast‑flux or short‑lived abuse campaigns targeting cryptocurrency users. No additional technical artifacts such as malware hashes or C2 endpoints have been published, so the exact draining mechanism remains unknown. Defenders should add reclaimwise.finance to deny‑list rules, monitor outbound connections to 185.158.133.1, and consider sinkholing the IP range. Continuous telemetry collection is advised to capture any evolving payloads or command‑and‑control activity associated with this crypto‑drainer operation.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب