claim-lucidly[.]finance
“Lucidly Finance”
Analysis of claim-lucidly.finance indicates this domain was actively flagged as a crypto drainer scam, with infrastructure and detection evidence confirming elevated risk. The domain, registered on March 23, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, resolved to IP 172.67.182.38, hosted by Cloudflare in Canada. While the site is currently offline, historical records show it was blocked by four security vendors—PhishDestroy, MetaMask, ScamSniffer, and SEAL—aligning with its classification as a crypto scam. Five of 94 security vendors on VirusTotal flagged the domain at the time of scanning, though the specific detection rules are not disclosed.
The page title, 'Lucidly Finance,' suggests an attempt to mimic a legitimate financial service, though no brand impersonation is confirmed in available data. Infrastructure analysis reveals the use of Cloudflare nameservers (alexandra.ns.cloudflare.com and jerry.ns.cloudflare.com) and technologies including Framer Sites, React, HSTS, and HTTP/3. The absence of an SSL certificate is notable but not definitive for malicious activity, as Cloudflare may handle encryption at the edge. Gridinsoft assigned a trust score of 0/100, reinforcing the domain's high-risk status.
Defenders should treat this domain as compromised and maintain blocks in web gateways, endpoint protection, and crypto wallet security tools. Given its offline status, further forensic analysis may be limited, but historical DNS and WHOIS records should be preserved for potential investigations. No evidence links this domain to broader phishing campaigns or known threat actor infrastructure at this time.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-15 02:55:50 UTC
Forensic Intelligence
Technologies · 5 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of claim-lucidly.finance · checked Mar 24, 2026
Evidence & External Reports
PD-20260324-662496 Recipient: abuse@nicenic.net, compliance@icann.org Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive