claim-uscrgov[.]com
“$USCR Airdrop - Welcome”
证据摘要
The domain claim-uscrgov.com was created on 21 February 2026 and is currently offline. DNS resolution points to IP address 66.29.148.128, an address owned by Namecheap, Inc. (AS22612) and geolocated to the United States. The site presented a page titled "$USCR Airdrop - Welcome", a classic airdrop‑style lure that aligns with the documented Airdrop Scam phishing kit. The domain is listed on a single security blocklist and has been actively blocked by PhishDestroy, indicating that at least one external feed has categorized it as malicious.
An SSL certificate identified as R12 was observed during the brief capture window; the presence of a certificate does not imply trust, but it confirms that the site was serving HTTPS traffic. VirusTotal records show that the host was scanned by 93 independent engines without any detections at the time of analysis; however, the lack of detections does not constitute evidence of safety and should not be interpreted as such. No additional content, payload, or redirect behavior has been publicly disclosed, so the exact mechanism used to drain cryptocurrency wallets remains unverified.
Given the combination of a recent registration, use of a known airdrop phishing kit, presence on a blocklist, and association with a crypto‑drainer campaign, defenders should treat claim-uscrgov.com as a high‑confidence indicator of compromise. Recommended mitigations include adding the domain and its resolved IP to outbound filtering rules, monitoring DNS queries for the domain or its IP, and ensuring that endpoint protection solutions are updated to flag any related URLs or executable payloads. Continued observation of threat‑intel feeds for re‑appearance or new artifacts is advised.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控