# PhishDestroy threat dossier — claude-ai.cyou ================================================================ Fetched: 2026-07-30 21:46:12 UTC Canonical: https://phishdestroy.io/domain/claude-ai.cyou/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Cluster25, CRDF, Ermes, Gridinsoft, SOCRadar URLQuery: 3 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.46.254 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: GLOBAL ASSET DOMAINS INC Nameservers: arushi.ns.cloudflare.com, kevin.ns.cloudflare.com Registered: 2026-07-22 Expires: 2027-07-22 Page title: Claude ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-20 Status: INVALID chain Fingerprint: 305a68a1ba59312f241cd2933fb112b98d44c4d957a74832a9fdc0b24b885ada ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-26 14:43:18 UTC (by PhishDestroy tracker) First reported: 2026-07-26 12:45:16 UTC (abuse notice filed) Last verified: 2026-07-30 21:21:05 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f9e72-3c19-76af-b685-7d478b997483/ URLQuery: https://urlquery.net/report/7cdec372-8126-4435-a6b8-2717c9155cc9 Wayback Machine: https://web.archive.org/web/*/claude-ai.cyou crt.sh CT logs: https://crt.sh/?q=%25.claude-ai.cyou Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=claude-ai.cyou AlienVault OTX: https://otx.alienvault.com/indicator/domain/claude-ai.cyou URLhaus: https://urlhaus.abuse.ch/host/claude-ai.cyou/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 14:44:11 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is claude-ai.cyou a phishing site? The domain claude-ai.cyou was registered on July 22, 2026 through GLOBAL ASSET DOMAINS INC and is served by Cloudflare nameservers arushi.ns.cloudflare.com and kevin.ns.cloudflare.com. DNS resolution points to the IP address 104.21.46.254, a Cloudflare edge node that provides generic content delivery and does not disclose the underlying hosting infrastructure. The domain appears on a single security blocklist, identified by PhishDestroy, indicating that at least one external threat‑intelligence source has flagged it for malicious activity. VirusTotal analysis shows that 2 of 91 security vendors have marked the domain as suspicious, confirming limited but non‑trivial detection by automated scanners. No additional public blocklists, Safe Browsing entries, or open threat‑exchange (OTX) references are currently listed for this domain. The short lifespan—only four days from registration to the report date—combined with the use of a reputable CDN and a minimal detection footprint suggests a deliberate attempt to leverage the anonymity and performance benefits of Cloudflare while evading rapid reputation buildup. Defenders should treat the domain as high‑risk, given its classification as a generic phishing site and its presence on PhishDestroy. Recommended actions include adding the domain to outbound and inbound firewall deny lists, monitoring DNS queries for the associated IP address, and employing URL filtering solutions that reference the blocklist entry. Continuous re‑evaluation is advised, as additional detections may emerge from broader scanning platforms or victim reports, potentially increasing the detection count and expanding blocklist coverage. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260726-2DFEE2 TLS cert SHA-256: 305a68a1ba59312f241cd2933fb112b98d44c4d957a74832a9fdc0b24b885ada ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/claude-ai.cyou/ JSON API: https://api.destroy.tools/v1/check?domain=claude-ai.cyou Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,122 domains (83,820 alive under monitoring, 110,042 confirmed takedowns/dead). Site: https://phishdestroy.io