listas[.]claims
“$LISTA Airdrop”
listas.claims — Contenido no disponible. Suplantación de marca: Across; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 1/93 (Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 58/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain listas.claims shows multiple indicators of malicious activity consistent with a crypto‑draining scam. The site was registered on February 21, 2026 and is presently taken offline, but historical data remain relevant for threat‑hunting. DNS resolution points to IP address 216.198.79.1, which geolocates to the United States and is owned by Lefkoff Industries. The hosting infrastructure does not appear to be shared with legitimate services, raising the likelihood of a dedicated malicious server.
The SSL certificate presented by the site is identified as R13, a certificate that lacks a recognized public‑trust chain and is commonly observed on fraudulent domains. The page title returned from the site is "$LISTA Airdrop," and the underlying code matches the publicly catalogued Airdrop Scam phishing kit, confirming the use of a known airdrop‑themed lure to entice cryptocurrency victims. VirusTotal analysis records a single positive detection out of 93 scanning engines, indicating at least one vendor has identified malicious behavior. Independent blocklist feeds list the domain on two security blocklists, and it has been explicitly blocked by the PhishDestroy and ScamSniffer filtering services.
These multiple independent detections reinforce the assessment that the domain is part of a coordinated crypto‑drain operation. Defenders should continue to block listas.claims at the DNS and proxy layers, monitor outbound connections to its resolved IP, and flag any internal traffic that attempts TLS handshakes with the R13 certificate. Since the site is currently offline, threat actors may re‑host the payload elsewhere; therefore, security teams should also watch for the Airdrop Scam kit signatures and similar page titles in future incidents. Continuous re‑query of VirusTotal and blocklist sources is advised to capture any new detections that could indicate re‑activation of the infrastructure.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.