claims-sentient[.]pro
“Sentient Airdrop”
claims-sentient.pro — Контент недоступен. Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 2/93 (Gridinsoft, SOCRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 58/100. Регистратор: Hostinger.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain claims-sentient.pro confirms its classification as a crypto drainer phishing site, targeting users through a fraudulent airdrop scheme. The domain was registered on February 21, 2026, via HOSTINGER operations, UAB, and resolves to the IP address 35.157.26.135, hosted on Amazon.com, Inc. infrastructure (AS16509) located in Germany. The site operated without an SSL certificate, a common red flag for phishing infrastructure. Its nameservers (dns1.p02.nsone.net, dns2.p02.nsone.net, dns3.p02.nsone.net, and dns4.p02.nsone.net) are associated with a legitimate DNS provider, though this does not mitigate the domain's malicious intent.
The page title, 'Sentient Airdrop,' aligns with the identified scam type of a crypto scam, specifically designed to deceive users into connecting wallets to drain funds. The domain appears on two security blocklists, including PhishDestroy and ScamSniffer, which have flagged it for malicious activity. While VirusTotal detections are limited (2 of 93 vendors), this does not diminish the credibility of the confirmed blocklist entries. The domain's current status is offline, though its prior activity and infrastructure remain relevant for defensive measures.
Defenders should prioritize blocking the domain and its associated IP (35.157.26.135) at the network level. Monitoring for similar domains registered through HOSTINGER operations, UAB, or resolving to the same IP range may help preempt related threats. Given the elevated risk level, organizations handling cryptocurrency transactions should alert users to the specific threat posed by 'Sentient Airdrop' scams and reinforce wallet security protocols. The exact content of the phishing page remains unanalyzed, but the available evidence strongly supports its classification as a crypto drainer operation.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260124-81180A Recipient: abuse@hostinger.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание