Is calude.ai safe or a scam?

calude.ai is a typosquatting domain that impersonates the legitimate claude.ai AI service.

Critical Risk
Phishing / Credential Theft

At a glance

Antivirus · registration · identity
Antivirus detections
14 flagged
14 malicious · 0 suspicious
ADMINUSLabs
Domain registration
Jul 11, 2023Registered
3 years oldAt scan time
Operator identity
Missing
No independently verifiable operator identity
Verified factsSaved with this scan
  1. 14 engines classified the URL as malicious and 0 as suspicious; 48 returned harmless, 30 returned undetected, and 0 returned no usable result.
  2. Operator identity: Missing. No independently verifiable operator identity
  3. gridinsoft.com: We flagged Calude.ai as phishing. The page behavior matches a common credential-theft flow: impersonation first, urgency second, data request last. calude.ai should not be treated as a safe website. Gridinsoft gives it a 1/100 trust score,
  4. joesandbox.com: The attacker registered the domain calude.ai, which mimics the legitimate claude.ai through a simple character transposition (swapping 'l' and 'a' to create 'cal' instead of 'cla'). This is a common typing error that users may make when att
  5. joesandbox.com: The URL 'calude.ai' is a classic example of typosquatting via transposition. It swaps the 'l' and 'a' in the brand name 'Claude', which is a globally recognized AI platform owned by Anthropic. ... Web search results confirm that calude.ai i

Intelligence

The domain name calude.ai was deliberately registered to resemble the well-known claude.ai service owned by Anthropic. The single-character transposition creates a common typing error that users may make when entering the legitimate address. The observed page shows minimal content consisting of the title 'calude.ai' and a prompt to 'Click here to enter', consistent with a landing page designed to initiate a credential-theft or malware-delivery sequence.

Evidence Map

Reputation
Concern

One or more reputation sources recorded a concern

Identity
Limited

No independently verifiable operator identity

Behavior
Unavailable

No usable behavior observation was saved

History
Observed

The domain was registered Jul 12, 2023 and was 3 years old at scan time.

Risk Factors
  • 1Domain name mimics claude.ai via 'l'/'a' transposition
  • 214 antivirus engines flagged the URL as malicious
  • 3Linked to credential-theft and InstallFix/ClickFix malware tactics

Domain impersonation of claude.ai

The domain calude.ai was registered on July 12, 2023. Its name is created by swapping the letters 'l' and 'a' in the legitimate brand 'claude', producing a classic typosquatting pattern that exploits common typing mistakes.

Observed page content

The captured page displays only the title 'calude.ai' and the text 'Click here to enter'. No contact email, phone number, or postal address appears anywhere on the page. No login form, countdown timer, or notification-bait copy was recorded.

Security-vendor findings

Fourteen antivirus engines classified the URL as malicious. Gridinsoft flagged the domain as phishing with a 1/100 trust score and described page behavior that follows a credential-theft flow of impersonation followed by urgency and data request. Joe Sandbox analysis identified the same transposition technique and linked the site to malware distribution via InstallFix/ClickFix tactics.

Registration details

Privacy protection is enabled on the registration record, and no independently verifiable operator identity was observed. The hosting IP showed an abuse-confidence score of 0/100 from zero reports, and the site presented a valid TLSv1.3 certificate.

Web Research

Gridinsoft reports that calude.ai matches a common credential-theft flow and assigns the domain a 1/100 trust score, with multiple security vendors blacklisting it.

Joe Sandbox analysis confirms the typosquatting technique and associates the domain with malware distribution via fake installation instructions.

gridinsoft.com

We flagged Calude.ai as phishing. The page behavior matches a common credential-theft flow: impersonation first, urgency second, data request last. calude.ai should not be treated as a safe website. Gridinsoft gives it a 1/100 trust score,

Single source
Source: gridinsoft.comView source
joesandbox.com

The attacker registered the domain calude.ai, which mimics the legitimate claude.ai through a simple character transposition (swapping 'l' and 'a' to create 'cal' instead of 'cla'). This is a common typing error that users may make when att

Single source
Source: joesandbox.comView source
joesandbox.com

The URL 'calude.ai' is a classic example of typosquatting via transposition. It swaps the 'l' and 'a' in the brand name 'Claude', which is a globally recognized AI platform owned by Anthropic. ... Web search results confirm that calude.ai i

Single source
Source: joesandbox.comView source
Automated Malware Analysis Report for http://calude.ai - Generated by Joe Sandbox

Joe Sandbox analysis identifies calude.ai as typosquatting of claude.ai via 'l'/'a' transposition and links it to malware distribution via InstallFix/ClickFix tactics

Single source
Source: Automated Malware Analysis Report for http://calude.ai - Generated by Joe SandboxView source

Threat Detection

Antivirus results, browser warnings, isolated page observations, and the threat pattern identified in this report.

Antivirus distribution
Recorded engine classifications, not a blanket clean bill
92 engines
Malicious14
Suspicious0
Harmless48
Undetected30
No result0
Antivirus consensus

Antivirus engine results

Result date Jul 20, 2026
Detection matrix
14 engines flagged this URL

This scan saved classifications from an antivirus network of 92 engines. Each malicious or suspicious classification is listed below by engine name and should be weighed with the rest of the report.

14Malicious0Suspicious48Harmless30Undetected0No result92Engines
0
of 92
ADMINUSLabs
Malicious· malicious
alphaMountain.ai
Malicious· phishing
BitDefender
Malicious· phishing
Certego
Malicious· phishing
Chong Lua Dao
Malicious· malicious
CyRadar
Malicious· phishing
Forcepoint ThreatSeeker
Malicious· phishing
G-Data
Malicious· phishing
Gridinsoft
Malicious· phishing
Lionic
Malicious· malicious
Lumu
Malicious· malware
Sophos
Malicious· phishing
VIPRE
Malicious· malware
Webroot
Malicious· malicious

14 antivirus engines flagged this URL. A single classification is not consensus by itself. Review its label together with the page, identity, behavior, and history evidence shown in this report.

Threat pattern
Phishing / Credential Theft
Threat tags
phishingmalwareTyposquatting
Scam tags
fake ai brand
Top reasons

Evidence behind this threat profile

3 reasons
  1. 1Domain name mimics claude.ai via 'l'/'a' transposition
  2. 214 antivirus engines flagged the URL as malicious
  3. 3Linked to credential-theft and InstallFix/ClickFix malware tactics
Scam-Type Likelihood

3 of 22 categories showed signals

This profile separates the site's primary threat from other patterns supported by the saved page evidence, public research, and security findings.

Top match: Phishing
Phishing
High likelihood
92/100
  • 14/92 AV engines flagged as malicious or phishing (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, Chong Lua Dao, CyRadar)
  • Gridinsoft flagged as phishing with 1/100 trust score and credential-theft flow pattern
  • Joe Sandbox analysis confirms typosquatting of claude.ai and credential-harvesting intent
Fake AI Brand
High likelihood
88/100
  • Domain calude.ai registered to impersonate Anthropic's claude.ai via character transposition
  • Joe Sandbox explicitly identifies it as mimicking the legitimate Claude AI platform
Malware
High likelihood
85/100
  • Joe Sandbox links the domain to malware distribution via InstallFix/ClickFix tactics
  • Multiple AV engines (ADMINUSLabs, Chong Lua Dao) explicitly labeled malicious

Technical Details

Identity, domain, infrastructure, and connection facts saved with this scan.

July 21, 2026 at 1:09 PM UTC

Identity

6 facts
Operator
Missing
On-domain email
Not observed
Other email
Not observed
Phone
Not observed
Postal address
Not observed
Social profiles
Not observed

Domain

8 facts
Domain age
3 years old
Registered
Jul 11, 2023
Registrar
Dynadot Inc
Expires
Jul 11, 2027
WHOIS updated
Jun 10, 2025
Registrant
Dynadot Privacy Service
Registration country
Unavailable
WHOIS privacy
Enabled

Infrastructure

14 facts
HTTPS
Valid certificate
TLS protocol
TLSv1.3
Certificate issuer
Let's Encrypt · YR1
Certificate subject
yen.com.au
Certificate valid from
Jul 7, 2026
Certificate valid to
Oct 5, 2026
Network address
103.224.182.238
ASN
Unavailable
Hosting organization
Trellian Pty. Limited
Country
US
Server
Apache
Site platform
Unavailable
IP reputation
0% confidence · 0 reports
Tor exit node
No

Connections

13 facts
Scan scope
Domain
Destination host
calude.ai
Redirects
0
Cross-domain redirect
No
Redirect status codes
200
Lookalike characters
Not observed
Internationalized domain
No
Page response
200
Observation coverage
Unavailable
Extracted links
Unavailable
Unique IPs contacted
Unavailable
Countries contacted
Unavailable
Referenced domains
0

What to do

1
Before interacting
Do not sign in

Do not visit or enter any information. The domain was created to impersonate the legitimate claude.ai service and has been linked to phishing and malware distribution.

2
If you already interacted

If you entered a password, change it on the official service by typing its known address yourself, enable two-factor authentication, and review recent account activity. Contact your bank if you also entered payment details.

Final Verdict

Do not sign in

Why this verdict

The domain calude.ai was registered July 12, 2023 and presents a landing page that mimics claude.ai through a simple 'l'/'a' transposition; 14 antivirus engines flagged the URL as malicious while open-web analysis links the site to credential-theft flows and InstallFix/ClickFix malware distribution.

Recommendation

Do not visit or enter any information. The domain was created to impersonate the legitimate claude.ai service and has been linked to phishing and malware distribution.

Key evidence

  1. 1Domain name mimics claude.ai via 'l'/'a' transposition
  2. 214 antivirus engines flagged the URL as malicious
  3. 3Linked to credential-theft and InstallFix/ClickFix malware tactics
Evidence: strongScope: DomainFresh scan: July 21, 2026 at 1:09 PM UTC

Safety FAQ

Is calude.ai safe to use?+

The domain calude.ai was registered July 12, 2023 and presents a landing page that mimics claude.ai through a simple 'l'/'a' transposition; 14 antivirus engines flagged the URL as malicious while open-web analysis links the site to credential-theft flows and InstallFix/ClickFix malware distribution.

What should I do about calude.ai?+

Do not visit or enter any information. The domain was created to impersonate the legitimate claude.ai service and has been linked to phishing and malware distribution.

How old is calude.ai?+

calude.ai is 3 years old and was registered jul 12, 2023.

What if I already interacted with calude.ai?+

If you entered a password, change it on the official service by typing its known address yourself, enable two-factor authentication, and review recent account activity. Contact your bank if you also entered payment details.

When was this report updated?+

This report reflects the scan completed July 21, 2026 at 1:09 PM UTC.