claim[.]rhetor[.]ai
“$RT Claim”
claim.rhetor.ai — Conteúdo indisponível. Representação da marca: Across; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 0 detections (engine total unavailable); PhishDestroy score 45/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain claim.rhetor.ai was registered on June 11, 2025 through Cloudflare, Inc., and is served by the authoritative nameservers clay.ns.cloudflare.com and daisy.ns.cloudflare.com. It resolves to the IPv4 address 216.150.16.193, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in the United States. The site presented the page title "$RT Claim" and employed a Let’s Encrypt R12 TLS certificate, indicating the presence of HTTPS encryption but offering no additional trust signals beyond the free certificate authority.
The domain appears on a single security blocklist, PhishDestroy, which has already taken the site offline as of the report date, July 24, 2026. VirusTotal analysis shows that 95 scanning engines evaluated the domain and reported no detections; however, the lack of detections does not constitute confirmation of safety, especially given the classification of the site as a crypto‑draining scam in the supplied intelligence. No further content analysis is available, and the exact methodology used to lure victims has not been disclosed.
Defensive recommendations include adding the domain to network and endpoint blocklists, monitoring DNS queries for the associated IP address and Cloudflare nameservers, and configuring web filtering to block HTTPS traffic to the host despite the valid certificate. Security teams should also audit logs for any prior connections to the IP range owned by Amazon, as compromised or misused cloud instances can be repurposed for malicious campaigns. Continuous observation of threat‑intel feeds for related domains using the same registrar or hosting infrastructure is advised to pre‑empt potential re‑deployment of the campaign under new domains.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo