claim[.]rhetor[.]ai
“$RT Claim”
claim.rhetor.ai — Контент недоступний. Уособлення бренду: Across; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 0 detections (engine total unavailable); PhishDestroy score 45/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain claim.rhetor.ai was registered on June 11, 2025 through Cloudflare, Inc., and is served by the authoritative nameservers clay.ns.cloudflare.com and daisy.ns.cloudflare.com. It resolves to the IPv4 address 216.150.16.193, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in the United States. The site presented the page title "$RT Claim" and employed a Let’s Encrypt R12 TLS certificate, indicating the presence of HTTPS encryption but offering no additional trust signals beyond the free certificate authority.
The domain appears on a single security blocklist, PhishDestroy, which has already taken the site offline as of the report date, July 24, 2026. VirusTotal analysis shows that 95 scanning engines evaluated the domain and reported no detections; however, the lack of detections does not constitute confirmation of safety, especially given the classification of the site as a crypto‑draining scam in the supplied intelligence. No further content analysis is available, and the exact methodology used to lure victims has not been disclosed.
Defensive recommendations include adding the domain to network and endpoint blocklists, monitoring DNS queries for the associated IP address and Cloudflare nameservers, and configuring web filtering to block HTTPS traffic to the host despite the valid certificate. Security teams should also audit logs for any prior connections to the IP range owned by Amazon, as compromised or misused cloud instances can be repurposed for malicious campaigns. Continuous observation of threat‑intel feeds for related domains using the same registrar or hosting infrastructure is advised to pre‑empt potential re‑deployment of the campaign under new domains.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога