# claimmoonbag.pages.dev — MALICIOUS > claimmoonbag.pages.dev is a crypto drainer site flagged by 14 of 95 VirusTotal vendors; avoid it and verify URLs on PhishDestroy. ## Summary PhishDestroy identifies claimmoonbag.pages.dev as an active crypto drainer domain designed to steal cryptocurrency assets from unwary users. This site currently operates with a high risk rating and is actively engaged in malicious activity targeting crypto wallets and transactions. Users who interact with this domain risk immediate financial loss as the platform executes unauthorized fund transfers to attacker-controlled addresses. This domain was flagged by 14 of 95 VirusTotal security vendors, registered through Cloudflare, Inc., and resolves to IP address 188.114.97.3. It has been blocked by MetaMask, SEAL, and ScamSniffer, appears on 3 security blocklists, and holds an SSL certificate issued by Google Trust Services. These indicators collectively confirm its malicious intent and operational status within the threat landscape. PhishDestroy strongly advises users to avoid claimmoonbag.pages.dev entirely due to its confirmed role as a crypto drainer. To verify the safety of any domain, users should conduct a scan using PhishDestroy’s real-time threat database before engaging with websites, especially those involved in cryptocurrency transactions. If you have already visited this domain or suspect exposure, disconnect your wallet immediately, revoke any unauthorized permissions, and perform a full security scan on your device. Always cross-check URLs using trusted threat intelligence platforms to prevent falling victim to crypto drainer attacks. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 14 vendors flagged - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["MetaMask", "SEAL", "ScamSniffer"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/1dd11182-c916-47f1-beb7-26a39b1dd429 - PhishDestroy: https://phishdestroy.io/domain/claimmoonbag.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/claimmoonbag.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/claimmoonbag.pages.dev/ Last updated: 2026-03-26