turtle[.]claims
साक्ष्य सारांश
Analysis of turtle.claims, registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on July 31, 2026, indicates active malicious infrastructure targeting cryptocurrency assets. The domain resolves to the IP address 172.67.158.71 and is served via Cloudflare, as evidenced by the authoritative nameservers chuck.ns.cloudflare.com and rafe.ns.cloudflare.com. The hosting choice suggests the operators are leveraging Cloudflare's CDN and obfuscation capabilities to hide the true origin of the payload. Turtle.claims appears on three independent security blocklists and has been explicitly blocked by PhishDestroy, MetaMask, and SEAL, reinforcing the assessment that the site is being used to lure victims into unauthorized crypto transactions.
VirusTotal scans show three of ninety‑one security vendors flagging the domain, providing additional vendor‑level corroboration of malicious intent. The threat classification is identified as a "crypto drainer," implying that the site likely attempts to intercept or redirect cryptocurrency withdrawals, though specific tactics (e.g., malicious smart‑contract injection, phishing of wallet credentials) have not been publicly disclosed. Open Threat Exchange (OTX) references or Safe Browsing verdicts are not currently available, and no page title or content analysis has been published, leaving the exact user‑facing experience unverified.
Defenders should proactively block network traffic to 172.67.158.71, enforce domain‑level denial for turtle.claims across proxy and firewall rules, and monitor for any DNS queries to the associated Cloudflare nameservers. Endpoint security solutions should be updated to recognize the three vendor detections reported by VirusTotal, and organizations using cryptocurrency wallets should educate users about the risk of unsolicited wallet‑address requests. Continuous re‑evaluation is recommended as additional intelligence, such as page content snapshots or OTX indicators, become available.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
परिणाम के संग्रहीत प्रमाण
परिणाम और टेकडाउन श्रेय
- परिणाम
protected- उपलब्धता
reachable_protected- कारण
cloudflare_challenge- कार्रवाईकर्ता
- Cloudflare
- तंत्र
challenge- विश्वसनीयता
- 85%
- पहला अवलोकन
- नवीनतम अवलोकन
प्रमाण SHA-256 8d87d5cdf9b4
पहचान समयरेखा
-
पहली दर्ज प्रविष्टि
पहला संग्रहीत मान: पहुँच योग्य
-
उपलब्धता
पहला संग्रहीत मान: अज्ञात
993d00c35140 -
डोमेन स्थिति
पहुँच योग्य → पहुँच योग्य नहीं
-
उपलब्धता
अज्ञात → सक्रिय सामग्री
5b513cb3620f -
उपलब्धता
सक्रिय सामग्री → संरक्षित
046bb81f1b0b -
उपलब्धता
संरक्षित → अज्ञात
83374d9d652c -
उपलब्धता
अज्ञात → संरक्षित
6e24df2ea459 -
उपलब्धता
संरक्षित → अज्ञात
7cebcfd4071c -
उपलब्धता
अज्ञात → संरक्षित
b52a3790851c -
उपलब्धता
संरक्षित → अज्ञात
ca255b61650a
सभी दिखाएँ (3)
-
उपलब्धता
अज्ञात → संरक्षित
acf0150f77e4 -
उपलब्धता
संरक्षित → अज्ञात
d8f7d37d7f95 -
उपलब्धता
अज्ञात → संरक्षित
8d87d5cdf9b4
समुदाय रिपोर्ट
0 समुदाय सदस्य ने रिपोर्ट किया; पहली बार 01/08/2026 को देखा गया
- रिपोर्ट किए गए विशिष्ट URL
- 1
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें
3 उच्च-विश्वसनीयता वाली तकनीकें पहचानी गईं
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
मिलते-जुलते डोमेन
79 संग्रहीत मिलते-जुलते डोमेन
सभी दिखाएँ (67)
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।