# waronusd1-claims.com — SUSPICIOUS > waronusd1-claims.com is a brand impersonation site labeled a crypto drainer. VirusTotal flags 4/95 vendors; impersonates WarOnUSD1. Do not interact. ## Summary PhishDestroy identifies waronusd1-claims.com as an active brand impersonation domain designed to mimic WarOnUSD1 and trick users into connecting crypto wallets that will be drained of assets. The site resolves to IP 188.114.97.3 and was registered on March 10, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED using a Let’s Encrypt SSL certificate. It is currently blocked by MetaMask and flagged by 4 of 95 VirusTotal security vendors, indicating elevated risk to visitors. This domain was registered just days ago and is already circulating with the specific intent to steal cryptocurrency through fake claim pages. Brand impersonation is a favored tactic among crypto drainers because it preys on user trust and urgency—promising rewards or access in exchange for wallet connections. Attackers often use newly registered domains with official-looking SSL certificates to appear legitimate at first glance, but automated defenses and browser extensions can catch these red flags early. If you visited waronusd1-claims.com, do not connect your wallet or enter any credentials. Disconnect immediately and revoke any wallet permissions you may have granted using tools like revoke.cash or your wallet’s built-in permission manager. Run a security scan on your device and consider rotating sensitive private keys or using a dedicated burner wallet for future interactions. Report the domain to your browser’s safe browsing program and warn others in the community to prevent further victimization. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: WarOnUSD1 ## Domain Intelligence - Registered: 2026-03-10 23:05:18 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 188.114.97.3 ## Detection Status - VirusTotal: 4 vendors flagged - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["MetaMask"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/2fdf4724-a09e-4029-9d36-fd0470a54986 - PhishDestroy: https://phishdestroy.io/domain/waronusd1-claims.com/ - LLM endpoint: https://phishdestroy.io/domain/waronusd1-claims.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/waronusd1-claims.com/ Last updated: 2026-03-23