# PhishDestroy threat dossier — claudeagent.fun ================================================================ Fetched: 2026-06-29 20:58:50 UTC Canonical: https://phishdestroy.io/domain/claudeagent.fun/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 96/100 (PhishDestroy scoring — see methodology below) Scam classification: Airdrop Scam Phishing kit: Airdrop Scam Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_split) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Gridinsoft Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 216.198.79.65 (US, Walnut) ASN: ASAS16509 AMAZON-02 - Amazon.com, Inc., US Hosting org: AS16509 Amazon.com, Inc. Registrar: Name.com, Inc. Nameservers: ns1.vercel-dns.com, ns2.vercel-dns.com Registered: 2026-05-14 Expires: 2027-05-14 Page title: ClaudeAgent — Airdrop Registration HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-14 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-26 15:17:25 UTC (by PhishDestroy tracker) First reported: 2026-06-26 13:18:36 UTC (abuse notice filed) Last verified: 2026-06-29 22:46:36 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f0412-deac-7488-94d3-2704568ddd1c/ URLQuery: https://urlquery.net/report/32349342-ef92-430d-8750-8e62081d4ff7 Wayback Machine: https://web.archive.org/web/*/claudeagent.fun crt.sh CT logs: https://crt.sh/?q=%25.claudeagent.fun Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=claudeagent.fun AlienVault OTX: https://otx.alienvault.com/indicator/domain/claudeagent.fun URLhaus: https://urlhaus.abuse.ch/host/claudeagent.fun/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-26 17:12:21 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, claudeagent.fun, is flagged for brand impersonation targeting cryptocurrency users through a fraudulent airdrop registration scheme. Analysis indicates the site mimics legitimate token distribution platforms, presenting itself as 'ClaudeAgent — Airdrop Registration' to deceive victims into disclosing wallet credentials or transferring funds. No specific drainer kit has been identified yet, but the page structure and branding suggest a typical airdrop scam infrastructure designed to harvest sensitive information. Infrastructure analysis reveals the domain resolves to IP address 216.198.79.65 and was registered through Name.com, Inc. on May 14, 2026. The SSL certificate is issued by Let's Encrypt, providing a false sense of security. As of the latest scan, VirusTotal reports 0/95 detections, indicating the domain has not yet been widely flagged by security vendors. Google Safe Browsing status is currently unlisted, and no blocklist entries have been recorded. The Gridinsoft trust score of 0/100 further corroborates the malicious intent. The domain remains active and under investigation, with no takedown or sinkholing actions observed. Users are advised to treat any interaction with claudeagent.fun as high-risk and avoid entering credentials or connecting wallets. Organizations should monitor for connections to 216.198.79.65 and consider preemptive blocking of the domain across security gateways. Given the lack of detections, reliance on traditional blocklists may not suffice; proactive threat hunting and endpoint monitoring are recommended to mitigate exposure. [Updates since narrative was generated:] - Public blocklists: now listed on 1 feed - VirusTotal detections: now 1/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260626-0722B3 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/claudeagent.fun/ JSON API: https://api.destroy.tools/v1/check?domain=claudeagent.fun Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 172,677 domains (13,179 alive under monitoring, 158,908 confirmed takedowns/dead). Site: https://phishdestroy.io