Notification and current-status evidence
The sent-report ledger records the first outgoing report at . It contains 3 outgoing records; the latest is dated . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
scanclaw[.]pro
“OpenClaw AI — Personal AI Assistant”
Resumo das evidências
scanclaw.pro has been flagged for hosting a crypto wallet drainer, a malicious tool designed to steal cryptocurrency from unsuspecting users. This threat is classified as a high-risk generic phishing attack, with the domain specifically engineered to deceive users into connecting their crypto wallets under false pretenses. The operation behind this site is likely automated, targeting victims through social engineering tactics such as fake giveaways, fraudulent airdrops, or spoofed login pages for popular crypto services. Given the active nature of the domain and its recent creation, users are strongly advised to avoid any interaction with this URL to prevent financial loss. PhishDestroy identifies scanclaw.pro as a newly emerged cyber threat, with its technical footprint revealing several red flags. The domain was registered through Global Domain Group LLC on April 04, 2026, and resolves to IP address 170.75.167.42. VirusTotal currently reports 17 out of 95 detections, indicating that mainstream antivirus engines have not yet flagged its malicious payload. The domain utilizes a Let's Encrypt SSL certificate, which adds a veneer of legitimacy but does not guarantee safety. Despite its clean VirusTotal score, the domain’s recent registration date and lack of historical data on blocklists suggest it is still in the early stages of deployment, making it a moving target for detection systems. Trust scores for this domain are currently nonexistent or critically low, as it has not been vetted by reputable security platforms. Mitigation steps for this crypto wallet drainer threat are critical to prevent irreversible financial damage. Users should immediately cease any interaction with scanclaw.pro, including avoiding clicks on links shared via email, social media, or messaging platforms. If a wallet connection was attempted, disconnect it immediately using wallet-specific security features, such as revoking permissions in MetaMask or other wallet interfaces. For organizations or individuals who may have fallen victim, report the incident to local cybercrime units and cryptocurrency recovery services, as funds sent to drainer addresses are often irrecoverable. Additionally, monitor connected wallets and revoke any suspicious smart contract approvals to limit potential exposure. PhishDestroy recommends verifying any unfamiliar domain through its real-time threat database before proceeding with transactions or login attempts to mitigate the risk of falling prey to similar attacks.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260407-1E237C- Título da página capturada
- OpenClaw AI — Personal AI Assistant
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Histórico de denúncias 3
- Denúncia 2 ⚠️ ESCALATION #2 (134h active): Phishing - scanclaw[.]pro
- Denúncia 3 ⚠️ ESCALATION #3 (270h active): Phishing - scanclaw[.]pro
- Denúncia 4 ⚠️ ESCALATION #4 (663h active): Phishing - scanclaw[.]pro
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | ipfs.io |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
VirusTotal
None → 0
-
VirusTotal
12 → 17
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of scanclaw.pro · checked May 28, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo