The domain hoodrat.claim-app.fun was created on July 30, 2026 and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. Its authoritative name servers are mona.ns.cloudflare.com and piotr.ns.cloudflare.com, indicating that the domain is hosted behind Cloudflare’s edge network. DNS resolution returns the IP address 172.67.133.15, which belongs to Cloudflare’s shared hosting pool and does not reveal a direct backend server. The domain currently appears on a single security blocklist and is specifically blocked by PhishDestroy, suggesting that at least one threat‑intelligence feed has identified malicious activity linked to this address. VirusTotal reports that the domain has been scanned by 91 vendors, none of which have raised a detection; this absence of alerts does not constitute a safety guarantee and should be weighed against other indicators.
The only concrete attribution for the threat type is the classification "crypto drainer" supplied in the report metadata. No additional context such as a page title, SSL certificate details, HTTP response codes, or observed traffic patterns has been disclosed, leaving the exact delivery mechanism and victim targeting unknown. The limited blocklist presence and the lack of vendor detections may reflect either a very recent deployment or evasion techniques that have not yet triggered signatures.
For defenders, the recommendation is to treat hoodrat.claim-app.fun as a high‑confidence indicator of a crypto‑draining campaign. Organizations should block DNS resolution to the domain at the network perimeter, add the IP address 172.67.133.15 to any existing deny lists, and monitor outbound connections for attempts to contact Cloudflare‑hosted endpoints that resolve to this address. Because the domain is still active, continuous telemetry collection and periodic re‑scanning with sandbox or URL‑analysis services are advised.