claim[.]runeswap[.]com
“LASER EYES”
claim.runeswap.com — Неперевірений. Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 2/91 (CRDF, Gridinsoft); PhishDestroy score 56/100. Реєстратор: NameCheap.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain claim.runeswap.com is currently active and classified as a crypto drainer with a high risk rating. The site returns HTTP status code 200 and serves a page titled LASER EYES. Infrastructure analysis shows the domain resolves to the IPv4 address 216.150.1.129, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in the United States. Technical profiling reveals the use of Webflow, Vercel, Twitter integration, HSTS, Google Hosted Libraries, and Google Font API. The authoritative name servers are dns1.registrar-servers.com and dns2.registrar-servers.com. The TLS certificate is issued by Let’s Encrypt under the R13 identifier, indicating a valid but short‑lived certificate. Registration details indicate the domain was created on 24 February 2021 through NameCheap, Inc. Reputation data shows the domain appears on one security blocklist and has been blocked by PhishDestroy. VirusTotal analysis reports a single detection out of 95 scanned security vendors, confirming at least one vendor flagged the site as malicious. The Gridinsoft trust score is 0 out of 100, reinforcing the malicious classification. These indicators collectively support the high‑risk crypto drainer designation. Defenders should add claim.runeswap.com and its resolving IP 216.150.1.129 to deny‑list rules across perimeter and endpoint controls. Continuous monitoring of the associated Amazon infrastructure for any new sub‑domains is advised. Updating intrusion detection signatures to include the observed technology stack and HSTS usage can reduce false negatives. Given the active status, organizations handling cryptocurrency assets should treat any traffic to this domain as hostile.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: runeswap.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain runeswap.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 6 identified
Visual website builder with hosted publishing.
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of claim.runeswap.com · checked Mar 2, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога