claim-esptein[.]pages[.]dev
“Jeffrey Epstein | Airdrop”
Registered just 3 days ago with Cloudflare, Inc., claim-esptein[.]pages[.]dev operates on an IP address of 172.66.46.249. The site has already accumulated 2 blocklist entries, indicating that it has been recognized as malicious by various security platforms. The rapid registration and immediate red flags suggest it may have been set up for fraudulent purposes, making it a site of concern for online security.
Currently, claim-esptein[.]pages[.]dev is still active, and PhishDestroy has taken steps to monitor this domain closely. The team has reported the site and continues to evaluate its activities to ensure that users are protected from potential phishing attempts associated with it.
Threat Response Pipeline
Public Blocklist Status
Evidence Capture
Domain Intelligence
faye.ns.cloudflare.com
karl.ns.cloudflare.com
stan.ns.cloudflare.com
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 172.66.46.249
More Domains at Cloudflare, Inc.
About This Report: claim-esptein.pages.dev
This domain security report for claim-esptein.pages.dev is maintained by PhishDestroy's automated threat intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal, 2 public blocklists, URLScan.io.
The site displays a page titled “Jeffrey Epstein | Airdrop”.
claim-esptein.pages.dev has been flagged by 2 security vendors as of February 27, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive



URLScan Report