Analysis indicates that claim-fwa.fun was registered on July 31, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently resolving to the IPv4 address 192.162.199.139. The domain is served by authoritative name servers ns3.my-ndns.com and ns4.my-ndns.com. Reputation checks show the domain appears on a single security blocklist and is actively listed by the PhishDestroy feed. VirusTotal has recorded a single positive detection out of 91 scanned engines, confirming malicious behavior.
The threat classification supplied is a crypto drainer, suggesting the site is used to illicitly siphon cryptocurrency assets from victims. No additional public indicators such as SSL certificate details, HTTP response codes, or page titles have been disclosed, leaving those aspects unverified. The short age of the domain—created less than two days before the report date—combined with its immediate appearance on a blocklist underscores a rapid deployment pattern typical of opportunistic financial scams. Defenders should add the IP address 192.162.199.139 to network‑level deny lists, block DNS resolution for claim-fwa.fun, and monitor outbound connections to that host.
Endpoint security solutions should incorporate the domain and its associated hash signatures from the single VirusTotal detection into their rule sets. Continuous observation of the hosting provider and name‑server infrastructure is advised, as changes may indicate migration to additional infrastructure. Organizations that handle cryptocurrency transactions should treat any traffic to this domain as high‑risk and enforce strict controls, including multi‑factor authentication and transaction whitelisting, to mitigate potential drain attempts.