claim-kaio[.]xyz
Category: Suspicious, Newly Registered
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of claim-kaio[.]xyz
claim-kaio[.]xyz appears to present itself as a cryptocurrency token claim portal branded as "KAIO." Based on the page title, on-page text, and screenshot, the site is designed for users who believe they are eligible for a KAIO token allocation or airdrop. The interface prominently invites visitors to connect an Ethereum wallet or connect through X, which suggests the site is intended to interact with crypto-wallet holders rather than provide general informational content.
The domain itself is not the main brand domain format one would typically expect for an established project, and the site appears to use a standalone claim-focused sub-branding approach on a newly registered .xyz domain. No clear operator identity is visible in the provided scan data, so ownership and organizational backing cannot be independently confirmed from the available information. Based on the content shown, the most fitting category is a cryptocurrency-related claim or airdrop portal.
Safety Assessment for claim-kaio[.]xyz
This website shows several risk indicators at the time of this scan. It was flagged by 6 out of 92 security engines, with detections described generically as suspicious, spam-related, or malicious by different scanners. In addition, multiple web-classification sources labeled it as a newly registered or suspicious website. The domain age is only 6 days, which materially increases uncertainty because many abusive crypto claim pages and short-lived phishing campaigns use very new domains.
The screenshot also raises caution because the page asks users to connect an Ethereum wallet to check eligibility for a token allocation. Wallet-connection prompts on newly registered crypto claim domains can be associated with phishing attempts, wallet-drainer campaigns, or deceptive airdrop offers, even when the page design looks polished. While blacklist databases checked in this scan were clean and the malware scan did not detect malicious files at the time of analysis, those signals do not rule out social-engineering or credential-harvesting risk on a fresh domain.
Based on these findings, this website may pose potential risks to visitors, particularly users considering connecting a cryptocurrency wallet or authorizing blockchain transactions.
Technical Description
The site uses a valid Let's Encrypt SSL certificate and is served through Cloudflare infrastructure, with the resolved IP associated with Cloudflare hosting in Toronto, Canada. Nameservers also point to Cloudflare, which may provide CDN and reverse-proxy protection. DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from DNSSEC validation.
From the scan data provided, no malicious files, external links, or iframes were detected during the malware scan, but the scan scope appears limited. The combination of a very recent registration date, lack of ranking, unsigned DNSSEC, and multi-engine security detections is more concerning than the TLS setup itself. In other words, the transport security appears standard, but the domain reputation and usage pattern remain questionable at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?