claimdunkins.com
“Lovable App”
This domain, claimdunkins.com, is currently flagged as an active crypto drainer operation with a high risk level.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Зведення доказів
This domain, claimdunkins.com, is currently flagged as an active crypto drainer operation with a high risk level. Registered on March 7, 2026, through GoDaddy.com, LLC, the domain resolves to the IP address 216.198.79.1 and presents a page titled 'Lovable App,' though the exact content and functionality of the site remain unconfirmed. Analysis indicates that the domain has been detected by two security blocklists and is recognized in two AlienVault OTX threat intelligence pulses, suggesting it has been linked to malicious activity in recent months. Infrastructure analysis reveals the use of Vercel for hosting and HSTS implementation, alongside a Let's Encrypt SSL certificate, which may be employed to lend an appearance of legitimacy. Detection metrics indicate limited but notable scrutiny, with two out of ninety-five security vendors on VirusTotal flagging the domain as malicious. The domain's trust score is rated at 0 out of 100 by Gridinsoft, reinforcing concerns about its credibility. What remains uncertain is the precise mechanism of the crypto drainer, as well as the specific cryptocurrency wallets or services being targeted. The domain's registration age—over four months at the time of this report—suggests it may be part of a longer-term campaign rather than a short-lived operation. Defenders should prioritize blocking this domain at the network level, particularly in environments where cryptocurrency transactions are common. Monitoring for connections to 216.198.79.1 and associated domains registered under the same infrastructure may also help identify related threats. Given its presence on multiple blocklists and threat intelligence feeds, this domain should be treated as a confirmed malicious asset until further evidence suggests otherwise.
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jul 12, 2026 · 18:38 UTCVirusTotal scanner detections updated from 1 to 2. Added scanner alerts: Gridinsoft, alphaMountain.ai.
-
VirusTotal Detections Update Mar 8, 2026 · 03:11 UTCVirusTotal scanner detections updated from 0 to 1. Added scanner alerts: SOCRadar.
-
Cloudflare Radar Scan Mar 7, 2026 · 05:55 UTCCloudflare Radar scan registered: View Radar report.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
- Server header seen by scanner
Vercel
Scanner note: alive_content: raw=ok; http=200; via=https_proxy; server=Vercel
Технології · 2 identified
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of claimdunkins.com · checked Jul 12, 2026
Повідомлення спільноти
Повідомив 1 учасник спільноти; уперше помічено 07.03.2026
- Збережені повідомлення
- 1
- Унікальні URL
- 1
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога