Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@name.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
reclaimfees[.]xyz
“SOL Reclaim”
reclaimfees.xyz — 클로킹됨 · 접근 가능. 사기 유형: Crypto Scam. 증거 요약: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); cloaking observed; PhishDestroy score 86/100. 등록기관: Name.com.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
This domain, reclaimfees.xyz, is flagged as a high-risk active crypto drainer phishing site. It was created on January 14, 2026, and remains operational as of July 12, 2026. The page title is 'SOL Reclaim', indicating a likely targeting of Solana blockchain users with a fake reclaim or fee refund scheme. VirusTotal reports 6 out of 95 security vendors flagging this domain, providing moderate but not universal detection. The domain appears on one security blocklist and is blocked by PhishDestroy. Infrastructure analysis reveals the site is hosted on Vercel, using Let's Encrypt SSL certificate issued by R13, and resolves to IP address 216.198.79.1 located in the United States under Lefkoff Industries. The HTTP response is a 307 redirect, common for phishing landing pages that quickly move victims to a malicious wallet connection prompt. The domain is registered through Name.com, Inc., with nameservers pointing to Vercel's DNS infrastructure. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the malicious assessment. The site employs HSTS for transport security, which is typical for legitimate services but can be abused to create a veneer of authenticity. Key uncertainties include the specific drainer kit used, the exact wallet addresses receiving stolen funds, and whether the campaign targets only Solana or other chains through redirects. No phishing kit vendor or brand has been identified from available data. Defenders should block this domain at DNS and email gateway levels, add the IP address 216.198.79.1 to blocklists, and monitor for related subdomains or variations. Users who may have visited this site should be warned to revoke any wallet permissions granted and to never connect their wallets to unknown sites. Continuous monitoring of Vercel-hosted phishing infrastructure and tracking of the 307 redirect chain may reveal additional associated domains.
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
사용 기술 · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of reclaimfees.xyz · checked Mar 23, 2026
증거 및 외부 보고서
PD-20260322-29224E Recipient: abuse@name.com 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.