claim-rewards[.]online
The domain claim-rewards.online is a crypto drainer, a type of malicious site designed to trick visitors into connecting their cryptocurrency wallets and approving fraudulent transactions. Once a user connects a wallet, the site can drain its contents by executing unauthorized transfers. This is not a typical phishing page that steals passwords; rather, it directly targets digital assets by exploiting wallet permissions.
PhishDestroy identifies this threat based on multiple indicators. The domain was created on June 16, 2026, which is suspiciously recent. It is registered through NameSilo, LLC, a known registrar sometimes abused for malicious domains. VirusTotal data shows that 8 out of 95 security vendors flag this domain as malicious. Additionally, the domain resolves to IP 103.119.217.27 and appears on three security blocklists. The SSL certificate is issued by Let's Encrypt, which is commonly used by both legitimate and malicious sites.
If you have visited claim-rewards.online and connected your crypto wallet, take immediate steps: revoke permissions for the site through your wallet's settings or a token approval checker, transfer any remaining assets to a new wallet, and monitor your accounts for unauthorized activity. Never connect your wallet to untrusted sites, and always verify the legitimacy of reward or airdrop offers. Stay safe online.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive