claim-kintara[.]gg
“Kintara: 5% TVL Distribution”
claim-kintara.gg — 未验证. 诈骗类型:Crypto Drainer. 证据摘要: VirusTotal 12/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 86/100. 注册商: Key Systems (http://ww….
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain claim-kintara.gg indicates an active crypto drainer phishing campaign targeting users through a fraudulent token distribution scheme. The domain, registered on June 15, 2026, via Key Systems, resolves to the IP address 188.114.97.3, hosted on Cloudflare infrastructure in Canada. Infrastructure analysis reveals Cloudflare nameservers (keaton.ns.cloudflare.com and oaklyn.ns.cloudflare.com), a configuration commonly observed in phishing operations due to its ease of deployment and obfuscation capabilities. The page title, 'Kintara: 5% TVL Distribution,' suggests an attempt to deceive users into believing they are interacting with a legitimate token distribution event associated with the Kintara project. However, no verified association with the Kintara brand has been confirmed, and the domain is classified as a crypto drainer, a threat type designed to siphon cryptocurrency assets from victims' wallets. Detection data from security vendors is limited but notable: one of 91 vendors on VirusTotal flags the domain as malicious, while four independent security blocklists have listed it. Additionally, the domain appears in two AlienVault OTX threat intelligence pulses, further corroborating its malicious classification. The SSL certificate, issued by Google Trust Services (WE1), is consistent with legitimate domains but does not mitigate the underlying threat. Defenders are advised to treat this domain as high-risk, particularly in environments where cryptocurrency transactions are conducted. Blocking the domain at the DNS or network level is recommended, alongside monitoring for connections to the associated IP address 188.114.97.3. Given the domain's recent registration and active status as of July 12, 2026, continued vigilance is warranted, as the campaign may evolve or expand its infrastructure.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。