claims-brevis[.]network
“Brevis Airdrop Registration Portal”
This domain, claims-brevis.network, was identified as part of a phishing infrastructure targeting Discord users through a fraudulent airdrop registration scheme. Registered on February 21, 2026, the domain resolved to IP address 172.67.182.231, hosted on Cloudflare's network (AS13335) in the United States. The site presented itself as a "Brevis Airdrop Registration Portal," a title consistent with social media phishing campaigns designed to harvest credentials or sensitive information. Analysis indicates the domain was flagged by seven security blocklists, including PhishDestroy, MetaMask, ScamSniffer, Polkadot, and SEAL, reflecting broad detection across the security community.
Four of 93 security vendors on VirusTotal marked the domain as malicious, further corroborating its abusive nature. The domain's SSL certificate was issued by WE1, a low-assurance provider often associated with short-lived phishing campaigns. Gridinsoft assigned a trust score of 0/100, reinforcing its classification as high-risk. Infrastructure analysis reveals the use of a known phishing kit labeled "Airdrop Scam," which aligns with the observed page title and scam type.
As of July 24, 2026, the domain has been taken offline, though defenders should monitor for re-emergence under similar naming conventions or hosting patterns. Organizations are advised to block the domain and associated IP at the perimeter, update detection rules for airdrop-themed phishing lures, and alert users to the risks of unsolicited token distribution offers. The exact content of the phishing page remains unanalyzed, but the available evidence confirms its intent to impersonate Discord-related services for fraudulent purposes.
Threat Response Pipeline
Public Blocklist Status
Forensic Intelligence
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive