claim-capicatr[.]lol
“CAPACITR MARKETS â Drop a Link. Discuss a Topic. Discover Markets. Derive a Trade.”
claim-capicatr.lol — 未验证. 诈骗类型:Crypto Drainer. 证据摘要: VirusTotal 17/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. 注册商: PDR.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of claim-capicatr.lol reveals a high‑risk crypto‑drainer infrastructure that remains active as of July 12, 2026. The domain was registered on May 19, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and is delegated to the Cloudflare nameservers ben.ns.cloudflare.com and keira.ns.cloudflare.com. DNS resolution points to the IP address 172.67.220.215, which belongs to Cloudflare, Inc. and is geolocated to Canada. An HTTPS service is available with a Let’s Encrypt/E8 certificate, and the web server returns HTTP 200 for the root request. The page title returned is "CAPACITR MARKETS — Drop a Link. Discuss a Topic. Discover Markets. Derive a Tr", confirming the presence of a marketing‑oriented front end that is typical for crypto‑drainer campaigns. Reputation data shows the domain appears on three security blocklists and has been flagged by PhishDestroy, MetaMask, and SEAL. VirusTotal scans report two detections out of ninety‑two security vendors, and AlienVault OTX lists the domain in one threat pulse. Gridinsoft assigns a trust score of 0 out of 100, indicating a lack of confidence in the host. While the exact payload or wallet harvesting mechanism has not been disclosed publicly, the classification as a crypto drainer suggests attempts to lure victims into transferring digital assets to attacker‑controlled addresses. Uncertainty remains regarding the specific social engineering vectors used and whether additional supporting infrastructure (e.g., command‑and‑control servers) exists beyond the observed IP. Defenders should block DNS resolution for claim-capicatr.lol, enforce TLS inspection to capture any malicious traffic, and monitor outbound cryptocurrency transactions for anomalous destinations. Continuous threat‑intel feed updates are recommended to capture any new indicators of compromise associated with this domain.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。