arabclub-claim[.]vercel[.]app
“ARABCLUB Hunt”
arabclub-claim.vercel.app — 콘텐츠를 사용할 수 없음. 브랜드 사칭: ["twitter"]; 사기 유형: Crypto Scam. 증거 요약: VirusTotal 2/95 (G-Data, Gridinsoft); 4 external blocklist matches; PhishDestroy score 82/100. 등록기관: Tucows.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Analysis indicates that the domain arabclub-claim.vercel.app was registered on 21 February 2026 through Tucows Domains Inc. The site was hosted on Amazon’s AS16509 infrastructure, resolving to IP 216.198.79.67 located in the United States. The TLS certificate is issued by Google Trust Services under the WR1 designation, and the server advertised HTTP Strict Transport Security. The web server responded with HTTP 451, indicating that the content is unavailable for legal reasons, and the current operational status is reported as offline. Open‑source intelligence classifies the site as a crypto‑drainer scam; the page title returned by the server is “ARABCLUB Hunt”.
The domain appears on five independent blocklists – PhishDestroy, ScamSniffer, Polkadot, Enkrypt and Codeesura – reinforcing the assessment of malicious intent. VirusTotal scans show that two of ninety‑five security vendors flagged the domain, providing additional corroboration of suspicious behavior. The available data does not include any observed payload, wallet addresses, or victim interaction details, so the specific mechanism of the crypto‑draining operation remains unknown. Likewise, no malware samples or command‑and‑control infrastructure have been disclosed.
Defenders should therefore treat the domain as high‑confidence malicious, enforce network‑level deny rules for the domain and its resolving IP, and add the listed blocklist entries to existing filtering solutions. Continuous monitoring of the IP range associated with AS16509 is advised, as the same infrastructure may host other illicit assets. Because the site is already offline, incident response teams should verify whether any recent outbound connections from internal assets targeted the domain before takedown, and, if found, initiate appropriate containment and forensic collection.
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 2 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 신뢰도 100%VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.