# PhishDestroy threat dossier — hoodrat.claim-app.fun ================================================================ Fetched: 2026-08-01 08:35:22 UTC Canonical: https://phishdestroy.io/domain/hoodrat.claim-app.fun/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer Targeted brand: Airdrop Scam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: CRDF, Fortinet, Gridinsoft, SOCRadar, URLQuery Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.133.15 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: mona.ns.cloudflare.com, piotr.ns.cloudflare.com Registered: 2026-07-30 Expires: 2027-07-30 Page title: Hoodrat | Airdrop ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-28 Status: INVALID chain Fingerprint: 9f741fe095516ea2d27e9ac900e4f5bc84d6fd6fdaabe64fd4601af30b0aeda7 Subject Alternative Names (related infrastructure — often same operator): - claim-app.fun ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-30 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-30 07:52:52 UTC (by PhishDestroy tracker) First reported: 2026-07-30 05:55:18 UTC (abuse notice filed) Last verified: 2026-08-01 08:20:20 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fb197-1c7d-7349-ac82-64c48da1fc7c/ URLQuery: https://urlquery.net/report/048f0a23-2a2b-4fc0-9615-efaa7d09b72b Wayback Machine: https://web.archive.org/web/*/hoodrat.claim-app.fun crt.sh CT logs: https://crt.sh/?q=%25.hoodrat.claim-app.fun Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=hoodrat.claim-app.fun AlienVault OTX: https://otx.alienvault.com/indicator/domain/hoodrat.claim-app.fun URLhaus: https://urlhaus.abuse.ch/host/hoodrat.claim-app.fun/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-30 07:53:12 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] hoodrat.claim-app.fun — Crypto Drainer Investigation Report The domain hoodrat.claim-app.fun was created on July 30, 2026 and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. Its authoritative name servers are mona.ns.cloudflare.com and piotr.ns.cloudflare.com, indicating that the domain is hosted behind Cloudflare’s edge network. DNS resolution returns the IP address 172.67.133.15, which belongs to Cloudflare’s shared hosting pool and does not reveal a direct backend server. The domain currently appears on a single security blocklist and is specifically blocked by PhishDestroy, suggesting that at least one threat‑intelligence feed has identified malicious activity linked to this address. VirusTotal reports that the domain has been scanned by 91 vendors, none of which have raised a detection; this absence of alerts does not constitute a safety guarantee and should be weighed against other indicators. The only concrete attribution for the threat type is the classification "crypto drainer" supplied in the report metadata. No additional context such as a page title, SSL certificate details, HTTP response codes, or observed traffic patterns has been disclosed, leaving the exact delivery mechanism and victim targeting unknown. The limited blocklist presence and the lack of vendor detections may reflect either a very recent deployment or evasion techniques that have not yet triggered signatures. For defenders, the recommendation is to treat hoodrat.claim-app.fun as a high‑confidence indicator of a crypto‑draining campaign. Organizations should block DNS resolution to the domain at the network perimeter, add the IP address 172.67.133.15 to any existing deny lists, and monitor outbound connections for attempts to contact Cloudflare‑hosted endpoints that resolve to this address. Because the domain is still active, continuous telemetry collection and periodic re‑scanning with sandbox or URL‑analysis services are advised. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260730-0DB30C Favicon MD5: 447a7c37385d6deef4649e5a05707036 TLS cert SHA-256: 9f741fe095516ea2d27e9ac900e4f5bc84d6fd6fdaabe64fd4601af30b0aeda7 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/hoodrat.claim-app.fun/ JSON API: https://api.destroy.tools/v1/check?domain=hoodrat.claim-app.fun Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,281 domains (91,207 alive under monitoring, 27,324 confirmed neutralized). Site: https://phishdestroy.io