claim-cherry[.]info
“Cherry.fun | Wallet Messaging”
Résumé des preuves
This domain is flagged as a high‑risk crypto drainer. The site presents the page title “Cherry.fun | Wallet Messaging”, indicating a wallet‑messaging interface likely used to solicit cryptocurrency transfers. The domain resolves to 188.114.96.3, which belongs to AS13335 Cloudflare, Inc., and the TLS certificate is issued by Let’s Encrypt (E7). Registration occurred on 12 Mar 2026 through NiceNIC International Group Co., Limited, with authoritative nameservers jade.ns.cloudflare.com and eoin.ns.cloudflare.com. VirusTotal records show 13 of 94 security vendors flag the host, and AlienVault OTX references the domain in 24 separate threat pulses. The IP address appears on four security blocklists, and the domain is listed by multiple anti‑phishing feeds. Technical fingerprinting reveals HSTS, Cloudflare Browser Insights, and HTTP/3 support, and the HTTP response code is 200. Gridinsoft assigns a trust score of 0 / 100, reinforcing the malicious classification. While the exact phishing page content has not been publicly released, the combination of a wallet‑related title, crypto‑drainer classification, and extensive vendor detections suggests an active campaign to trick users into sending cryptocurrency. Defenders should block the domain at network perimeter, add the IP address 188.114.96.3 to deny‑list rules, and monitor for any outbound connections to the associated wallet address if known. Continuous threat‑intel feeds should be consulted for updates, and any internal alerts referencing “Cherry.fun” or similar wallet‑messaging terminology should be investigated as potential compromise attempts.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
7 sources externes surveillées Aucune correspondance
Preuves du résultat enregistrées
Résultat et attribution du retrait
- Résultat
live_content- Disponibilité
content_live- Cause
content_served- Confiance
- 90%
- Première observation
- Dernière observation
SHA-256 de la preuve 803bb1803ba4
Chronologie de détection
-
VirusTotal
3 → 13
-
Disponibilité
Première valeur enregistrée : Inconnu
993d00c35140 -
Disponibilité
Inconnu → Contenu actif
ef5e55f24aca -
Disponibilité
Contenu actif → Inconnu
0f714bed1b5d -
Disponibilité
Inconnu → Contenu actif
97e6018af607 -
Disponibilité
Contenu actif → Inconnu
7cebcfd4071c -
Disponibilité
Inconnu → Contenu actif
752c4fccc0eb -
Disponibilité
Contenu actif → Inconnu
ca255b61650a -
Disponibilité
Inconnu → Contenu actif
53b9366af7bd -
Disponibilité
Contenu actif → Inconnu
d8f7d37d7f95
Tout afficher (5)
-
Disponibilité
Inconnu → Contenu actif
6f3c9b1a63a9 -
Disponibilité
Contenu actif → Inconnu
afa49a2b04dd -
Disponibilité
Inconnu → Contenu actif
770d6b84f94f -
Disponibilité
Contenu actif → Inconnu
e70d6b0bd31a -
Disponibilité
Inconnu → Contenu actif
803bb1803ba4
Signalements communautaires
Signalé par 1 membre de la communauté ; première observation le 12/03/2026
- Signalements enregistrés
- 1
- URL signalées uniques
- 1
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of claim-cherry.info · checked Jul 12, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif