Analysis of aster-tokenclaim.web.app as of July 28 2026 identifies an active infrastructure supporting a crypto‑drainer operation. The domain is registered through Google LLC, indicating use of a reputable registrar to obscure malicious intent. DNS resolution points to the IP address 199.36.158.100; however, the authoritative nameserver information could not be retrieved (NS_NOT_FOUND), limiting visibility into the hosting environment. Threat intelligence feeds have classified the site as a crypto drainer and assigned a high risk rating, consistent with its inclusion on two external blocklists and detection by the PhishDestroy and ScamSniffer services.
VirusTotal scans show that three out of ninety‑one antivirus and URL‑reputation engines flagged the domain, providing independent corroboration of malicious activity. No additional public indicators such as SSL certificate details, HTTP response codes, or page titles are currently available, leaving the exact payload delivery mechanism uncertain. The combination of registrar choice, active IP resolution, and multiple independent detections suggests a deliberate attempt to evade casual scrutiny while targeting cryptocurrency wallets. Defensive teams should immediately add 199.36.158.100 and aster-tokenclaim.web.app to network‑level deny lists, enforce DNS‑based filtering for the domain, and monitor outbound traffic for patterns associated with crypto‑wallet interactions.
Continuous re‑query of reputation services is advised, as the domain may acquire further detections or be repointed to new infrastructure. Where possible, sinkholing the IP address can disrupt command‑and‑control flow and provide additional telemetry for attribution. Given the high‑risk classification and active status, organizations handling cryptocurrency assets should treat any traffic to this domain as malicious and block it at perimeter and endpoint layers.