Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@name.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
reclaimfees[.]xyz
“SOL Reclaim”
reclaimfees.xyz — Terselubung · dapat dijangkau. Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); cloaking observed; PhishDestroy score 86/100. Registrar: Name.com.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, reclaimfees.xyz, is flagged as a high-risk active crypto drainer phishing site. It was created on January 14, 2026, and remains operational as of July 12, 2026. The page title is 'SOL Reclaim', indicating a likely targeting of Solana blockchain users with a fake reclaim or fee refund scheme. VirusTotal reports 6 out of 95 security vendors flagging this domain, providing moderate but not universal detection. The domain appears on one security blocklist and is blocked by PhishDestroy. Infrastructure analysis reveals the site is hosted on Vercel, using Let's Encrypt SSL certificate issued by R13, and resolves to IP address 216.198.79.1 located in the United States under Lefkoff Industries. The HTTP response is a 307 redirect, common for phishing landing pages that quickly move victims to a malicious wallet connection prompt. The domain is registered through Name.com, Inc., with nameservers pointing to Vercel's DNS infrastructure. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the malicious assessment. The site employs HSTS for transport security, which is typical for legitimate services but can be abused to create a veneer of authenticity. Key uncertainties include the specific drainer kit used, the exact wallet addresses receiving stolen funds, and whether the campaign targets only Solana or other chains through redirects. No phishing kit vendor or brand has been identified from available data. Defenders should block this domain at DNS and email gateway levels, add the IP address 216.198.79.1 to blocklists, and monitor for related subdomains or variations. Users who may have visited this site should be warned to revoke any wallet permissions granted and to never connect their wallets to unknown sites. Continuous monitoring of Vercel-hosted phishing infrastructure and tracking of the 307 redirect chain may reveal additional associated domains.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of reclaimfees.xyz · checked Mar 23, 2026
Bukti & Laporan Eksternal
PD-20260322-29224E Recipient: abuse@name.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive