claim[.]piasma[.]network
“Apache2 Ubuntu Default Page: It works”
Kanıt özeti
The domain claim.piasma.network was registered on 21 February 2026 and is currently listed as active. It has been identified as a cryptocurrency drainer used to lure victims into submitting private keys or transferring funds to fraudulent wallets. The site is already blocked by the PhishDestroy blocklist and appears on one additional security blocklist, indicating that at least one external repository has flagged the host.
Technical resolution shows the domain resolves to the IP address 104.21.24.106, which is part of the Cloudflare network (AS13335) and geolocated to the United States. An HTTPS endpoint is presented with a certificate labeled WE1, and the web server returns HTTP 200 responses, confirming that the page is actively serving content. The Gridinsoft trust engine assigns a score of 0 out of 100, reflecting an extremely low reputation.
VirusTotal scans have returned 14 positive detections out of 95 security vendors, reinforcing the malicious classification. The combination of a zero trust score, multiple vendor flags, and active blocklist entries suggests a high‑confidence crypto‑draining operation. No additional infrastructure such as command‑and‑control servers or secondary domains has been disclosed, leaving the full scope of the campaign uncertain.
Defenders should add claim.piasma.network to local deny lists, enforce outbound filtering for connections to the associated IP, and monitor for attempted cryptocurrency transactions that reference the domain. Continuous re‑evaluation of the host’s reputation is advised, as further indicators may emerge. Network telemetry that captures TLS handshakes to the WE1 certificate can aid in early detection of compromised clients.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin