clear-vault[.]online
Evidence Summary
Clear-vault.online is identified as a generic phishing domain, specifically a crypto drainer, and is currently offline. This domain does not appear to impersonate any specific brand. It was created on February 21, 2026, and has been flagged by 7 of 95 VirusTotal vendors, indicating a significant risk to users who may have interacted with it. The domain was registered through HOSTINGER operations, UAB, and is listed on 1 security blocklist, further highlighting its malicious nature.
The domain's registration and hosting details, including its IP address, are critical in understanding the scope of the threat. While the exact IP is not provided, the fact that it is flagged by a notable number of security vendors on VirusTotal suggests a high level of malicious activity. The creation date of February 21, 2026, indicates that this is a relatively new domain, likely set up with the intention of perpetrating phishing attacks. The registrar, HOSTINGER operations, UAB, is a legitimate service, but in this case, has been used for nefarious purposes. With a trust score that is likely to be very low due to its presence on a security blocklist, users are advised to exercise extreme caution.
Given its current offline status, it appears that efforts have been made to mitigate the threat posed by clear-vault.online. However, users who may have previously interacted with the domain should be vigilant and monitor their accounts for any suspicious activity. PhishDestroy recommends verifying the legitimacy of any website before entering sensitive information and keeping software up to date to protect against potential vulnerabilities. The fact that clear-vault.online was able to be flagged and taken offline demonstrates the importance of community reporting and the use of tools like VirusTotal in identifying and mitigating phishing threats.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Detection timeline
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of clear-vault.online · checked Mar 2, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive