claim.ethgas[.]sbs
Category: Malware Sites
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of claim.ethgas[.]sbs
The website appears to present itself as an Ethereum-related service offering a "Gas Fees Refund" or "Claim Refund" function. Based on the screenshot, it invites visitors to calculate a refund amount by entering an ETH address and also includes a prominent "Connect Wallet" button, suggesting that it is aimed at cryptocurrency users and may be attempting to interact with browser wallets.
The domain name claim.ethgas[.]sbs is not an official-looking Ethereum Foundation domain and appears to be a standalone third-party site using Ethereum branding and terminology. Its content is focused on cryptocurrency refund claims rather than general blockchain education, wallet software, or exchange services, which may indicate a narrowly targeted campaign or promotional landing page.
No clear operator identity, company details, or organizational ownership information are visible from the provided scan data and screenshot. Based on the domain naming, page design, and wallet-connection prompt, the site appears to be a crypto-themed landing page that may be intended to collect wallet interactions from visitors.
Safety Assessment for claim.ethgas[.]sbs
The scan results show mixed signals at the time of this scan. One out of 91 security engines flagged the domain, and one web-classification source categorized it as a malware-related site, while other blacklist checks and the malware file scan did not detect threats. This limited detection count does not by itself confirm harmful activity, but it is still a cautionary indicator when combined with the site’s behavior and presentation.
Several contextual risk factors increase concern. The domain was created very recently (age: 0 days), has no established traffic ranking, and uses a cryptocurrency-themed refund claim that asks users to enter an ETH address and connect a wallet. In practice, newly created crypto claim pages that request wallet connections may be associated with phishing or wallet-draining schemes, especially when they use well-known blockchain branding without clear operator attribution.
The screenshot also shows a challenge-platform URL path associated with an anti-bot or access-control layer, which can be legitimate, but it may also make independent inspection harder. Based on these findings, this website may pose potential risks to visitors, particularly anyone considering connecting a cryptocurrency wallet or submitting blockchain account details.
Technical Description
The domain is hosted behind Cloudflare infrastructure and resolves to a Cloudflare IP in Canada. It uses a valid Let's Encrypt SSL certificate, which indicates encrypted HTTPS transport is available, but certificate validity alone does not establish trustworthiness. The nameservers are also on Cloudflare, and DNSSEC appears to be unsigned at the time of this scan.
From a technical risk perspective, the strongest concerns are not the TLS setup but the domain’s extreme newness, lack of reputation history, and the combination of crypto-wallet interaction prompts with a sparse trust profile. The scan found no flagged files and no flagged external links in the limited crawl, but the site was still flagged by 1 security engine and categorized by one provider as malware-related at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?