सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 4। किसी मैच की रिपोर्ट करने वाली सार्वजनिक ब्लॉक सूचियाँ: 2। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

claro-rewardsd[.]top

“Claro Perú: Celulares, Internet, Fibra óptica, Postpago y más”

धमकी भरा फैसला ऊँचा 66/100 साक्ष्य स्कोर
उपलब्धता असत्यापित वर्तमान पहुंच योग्यता असत्यापित है
वायरस का कुल पता लगाना: 4/91 संग्रहीत ब्लॉकलिस्ट मिलान: 2 URLQuery threat systems: 1 alert ब्रांड प्रतिरूपण: Claro
13/05/2026 Claro CDN
रिपोर्ट सारांश

claro-rewardsd.top — असत्यापित. ब्रांड प्रतिरूपण: Claro; घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. रजिस्ट्रार: Dynadot.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
उच्च
संदर्भ
3F21F434
स्कोर
66/100

PhishDestroy identifies claro-rewardsd.top as an under-investigation epsilon phishing domain actively impersonating the legitimate Claro Rewards loyalty program. The domain employs a deceptive typo-squatting pattern (rewardsd vs rewards) designed to harvest credentials and payment details from unsuspecting Claro users. While no drainer kit artifacts were detected in open-source intelligence, the page structure suggests a credential harvesting flow targeting Spanish-speaking mobile subscribers in Latin America. This domain exhibits multiple red flags confirmed by forensic analysis. VirusTotal currently reports 2/95 detections despite active hosting on AS13335 via IP 172.67.178.216. The domain was registered through Dynadot LLC on May 11, 2026, just days ago, indicating preemptive domain acquisition for campaign deployment. Google Safe Browsing has not yet flagged this resource, and public blocklists show zero historical detections, highlighting the novelty of this infrastructure. The Let's Encrypt SSL certificate covers the apex domain but provides no organizational validation, a common tactic to establish false legitimacy. claro-rewardsd.top remains in active status with no takedown interventions applied. Users should immediately block both the domain and resolving IP at network and endpoint levels. Given the 2/95 VirusTotal score and absence from blocklists, this campaign likely represents a newly deployed epsilon variant with potential for rapid expansion. Remaining risk is assessed as high due to the combination of recent registration, clean reputation history, and active infrastructure deployment. Organizations should deploy DNS sinkholing and update firewall rules to quarantine traffic to 172.67.178.216 while user education campaigns warn against interacting with Claro-themed domains outside official channels.

VirusTotal
VirusTotal
4 det.
URLQuery
यूआरएलक्वेरी
1 threat alert
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
Let's Encrypt
आयु
3 mo
देखी गई स्थिति
असत्यापित
PhishDestroy
विनाश सूची
सूचीबद्ध
डेटा कवरेज VirusTotal 4 / 91 यूआरएलक्वेरी 1 threat-system alert फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक 14 जाँच पूरी — कोई ब्लॉक नहीं TLS valid certificate, 88d कौन है 3 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU claro-rewardsd.top malicious Sinkholed

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
11/13

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

पेज शीर्षक
Claro Perú: Celulares, Internet, Fibra óptica, Postpago y más
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 88 days

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN nginx · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden एज-आईपी प्रतिष्ठा इस डोमेन के लिए जिम्मेदार नहीं है।
रजिस्ट्रार Dynadot US(US)
दुरुपयोग संपर्कabuse@dynadot.com
IP पता 172.67.178.216 CDN
भौगोलिक स्थानCA Toronto, CA
नेटवर्कAS13335 · Cloudflare, Inc.
रिवर्स IPviewdns.info → rapiddns.io →
मूल आईपी सीडीएन प्रॉक्सी के पीछे छिपा हुआ है। किनारे के पते के लिए रिवर्स-आईपी परिणामों में असंबंधित किरायेदार शामिल हैं; मूल का पता लगाने के लिए निष्क्रिय DNS या प्रमाणपत्र-पारदर्शिता डेटा की आवश्यकता होती है।
पंजीकरणनिर्मित 13/05/2026 (98d)
Elapsed Since First Report 32h
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: असत्यापित.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला13/05/2026
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://claro-rewardsd.top/
नेमसर्वरsevki.ns.cloudflare.com.
TLS Fingerprint
TLS Observationvalid from 11/05/2026scanned 13/05/2026
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।
तकनीकें · 18 identified
Nginx
Web servers Reverse proxies

Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.

nginx.org 100% विश्वास
Amazon Web Services
PaaS

Amazon Web Services (AWS) is a comprehensive cloud services platform offering compute power, database storage, content delivery and other functionality.

aws.amazon.com 100% विश्वास
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 100% विश्वास
VWO
Analytics A/B Testing

VWO is a website testing and conversion optimisation platform.

vwo.com 100% विश्वास
Slick
JavaScript libraries
kenwheeler.github.io 100% विश्वास
Segment
Customer data platform

Segment is a customer data platform (CDP) that helps you collect, clean, and control your customer data.

segment.com 100% विश्वास
reCAPTCHA
सुरक्षा

reCAPTCHA is a free service from Google that helps protect websites from spam and abuse.

www.google.com 100% विश्वास
OneSignal
Marketing automation A/B Testing

OneSignal is a customer engagement messaging solution.

onesignal.com 100% विश्वास
OWL Carousel
JavaScript libraries

OWL Carousel is an enabled jQuery plugin that lets you create responsive carousel sliders.

owlcarousel2.github.io 100% विश्वास
Lightbox
JavaScript libraries

Lightbox is small javascript library used to overlay images on top of the current page.

lokeshdhakar.com 100% विश्वास
jsDelivr
CDN

JSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.

www.jsdelivr.com 100% विश्वास
jQuery
JavaScript libraries

jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.

jquery.com 100% विश्वास
HSTS
सुरक्षा

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100% विश्वास
Google Tag Manager
Tag managers

Google Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.

www.google.com 100% विश्वास
Google Analytics
Analytics

Google Analytics is a free web analytics service that tracks and reports website traffic.

google.com 100% विश्वास
Facebook Pixel
Analytics

Facebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.

facebook.com 100% विश्वास
crypto-js
JavaScript libraries

crypto-js is a JavaScript library of crypto standards.

github.com 100% विश्वास
cdnjs
CDN

cdnjs is a free distributed JS library delivery service.

cdnjs.com 100% विश्वास
Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

4 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed Previous stored snapshot: 4 detections
alphaMountain.ai
CRDF
Gridinsoft
SOCRadar

साक्ष्य और बाहरी रिपोर्टें

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/claro-rewardsd.top"
  title="PhishDestroy threat report for claro-rewardsd.top"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।