MALICIOUS — CRITICAL
claim-250[.]pages[.]dev
Security analysis of claim-250.pages.dev covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
- VirusTotal
- 10/91
- Blocklists
- 3 · MetaMask, ScamSniffer
- Kullanılabilirlik
- Bilinen son aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
claim-250.pages.dev — Bilinen son aktif (HTTP 200). Dolandırıcılık türü: Fake Airdrop. Kanıt özeti: VirusTotal 10/91 (alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker, Fortinet); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 100/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
claim-250.pages.dev: Confirmed Crypto Drainer Scam
Security analysis of claim-250.pages.dev covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
Analysis of claim-250.pages.dev shows a newly registered (May 28, 2026) site hosted behind Cloudflare’s network (nameservers faye.ns.cloudflare.com and stan.ns.cloudflare.com, ASN 13335, IP 172.66.45.44 located in the United States). The site presents the page title "Just Buy $250 Worth | Airdrop," which aligns with a fake airdrop campaign classified as a crypto drainer. Technical fingerprints include a valid Let’s Encrypt certificate (E7), enforced HSTS, HTTP/3 support, and an HTTP 200 response. The domain is identified by a known Airdrop phishing kit and receives a Gridinsoft trust score of 0/100. Independent security services have flagged the site: three of ninety‑one VirusTotal scanners reported malicious behavior, and four external blocklists (PhishDestroy, MetaMask, SEAL, ScamSniffer) already block it. The evidence confirms the domain is actively used for a crypto‑draining scam. Uncertainty remains regarding the exact payload or wallet address collection mechanisms, as no page content beyond the title has been examined. Defenders should immediately block claim-250.pages.dev at network and endpoint layers, add it to URL filtering policies, and monitor for any DNS queries to the associated Cloudflare IP range. Continuous watch for similar domains created in the same period and using the same Airdrop kit is recommended to curb further propagation.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of claim-250.pages.dev · checked May 28, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.