thetatoken[.]claimreward[.]site
“Theta Network”
thetatoken.claimreward.site — Contenido no disponible (HTTP 502). Suplantación de marca: Across; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 2/94 (alphaMountain.ai, SOCRadar); URLQuery 1 alert; PhishDestroy score 60/100. Registrador: Hostinger.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain thetatoken.claimreward.site is a confirmed brand impersonation phishing site targeting the OKX cryptocurrency exchange. It poses as the Theta Network to trick users into connecting their cryptocurrency wallets, which would enable attackers to drain funds. The site has been taken offline, but it posed an elevated risk due to its use of a legitimate-looking domain and technical infrastructure.
Technical analysis shows that thetatoken.claimreward.site was flagged by 2 of 95 VirusTotal vendors, including alphaMountain.ai and SOCRadar. It was registered through HOSTINGER operations, UAB on 2026-03-03 17:32:29 and resolved to IP address 66.78.41.20 located in the Netherlands (AS401605 Web Host Most, LLC). The site appeared on 1 security blocklist (PhishDestroy) and used technologies including LiteSpeed, HSTS, and HTTP/3. No SSL issuer information was available. The page title observed was 'Theta Network,' and the domain uses nameservers ns1.server1.webhostmost.com, ns2.server2.webhostmost.com, and ns3.server3.webhostmost.
Users who interacted with thetatoken.claimreward.site should immediately revoke any token approvals granted to the site and move cryptocurrency funds to a new wallet created on a secure device. Since this is a cryptocurrency drainer phishing attack, no passwords were compromised, but monitoring for unauthorized transactions is essential. Report the domain to cryptocurrency platforms and blocklist services like PhishDestroy to prevent future use. As the site is offline, no further action is needed regarding the domain itself.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | thetatoken.claimreward.site |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: claimreward.site
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain claimreward.site behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 3 identified
High-performance web server compatible with Apache configurations.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of thetatoken.claimreward.site · checked Mar 17, 2026
Datos y informes externos
PD-20260317-01196B Recipient: abuse@hostinger.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.