Is calude.ai safe or a scam?
calude.ai is a typosquatting domain that impersonates the legitimate claude.ai AI service.
At a glance
Antivirus · registration · identity- 14 engines classified the URL as malicious and 0 as suspicious; 48 returned harmless, 30 returned undetected, and 0 returned no usable result.
- Operator identity: Missing. No independently verifiable operator identity
- gridinsoft.com: We flagged Calude.ai as phishing. The page behavior matches a common credential-theft flow: impersonation first, urgency second, data request last. calude.ai should not be treated as a safe website. Gridinsoft gives it a 1/100 trust score,
- joesandbox.com: The attacker registered the domain calude.ai, which mimics the legitimate claude.ai through a simple character transposition (swapping 'l' and 'a' to create 'cal' instead of 'cla'). This is a common typing error that users may make when att
- joesandbox.com: The URL 'calude.ai' is a classic example of typosquatting via transposition. It swaps the 'l' and 'a' in the brand name 'Claude', which is a globally recognized AI platform owned by Anthropic. ... Web search results confirm that calude.ai i
Intelligence
The domain name calude.ai was deliberately registered to resemble the well-known claude.ai service owned by Anthropic. The single-character transposition creates a common typing error that users may make when entering the legitimate address. The observed page shows minimal content consisting of the title 'calude.ai' and a prompt to 'Click here to enter', consistent with a landing page designed to initiate a credential-theft or malware-delivery sequence.
Evidence Map
One or more reputation sources recorded a concern
No independently verifiable operator identity
No usable behavior observation was saved
The domain was registered Jul 12, 2023 and was 3 years old at scan time.
- 1Domain name mimics claude.ai via 'l'/'a' transposition
- 214 antivirus engines flagged the URL as malicious
- 3Linked to credential-theft and InstallFix/ClickFix malware tactics
Domain impersonation of claude.ai
The domain calude.ai was registered on July 12, 2023. Its name is created by swapping the letters 'l' and 'a' in the legitimate brand 'claude', producing a classic typosquatting pattern that exploits common typing mistakes.
Observed page content
The captured page displays only the title 'calude.ai' and the text 'Click here to enter'. No contact email, phone number, or postal address appears anywhere on the page. No login form, countdown timer, or notification-bait copy was recorded.
Security-vendor findings
Fourteen antivirus engines classified the URL as malicious. Gridinsoft flagged the domain as phishing with a 1/100 trust score and described page behavior that follows a credential-theft flow of impersonation followed by urgency and data request. Joe Sandbox analysis identified the same transposition technique and linked the site to malware distribution via InstallFix/ClickFix tactics.
Registration details
Privacy protection is enabled on the registration record, and no independently verifiable operator identity was observed. The hosting IP showed an abuse-confidence score of 0/100 from zero reports, and the site presented a valid TLSv1.3 certificate.
Web Research
Gridinsoft reports that calude.ai matches a common credential-theft flow and assigns the domain a 1/100 trust score, with multiple security vendors blacklisting it.
Joe Sandbox analysis confirms the typosquatting technique and associates the domain with malware distribution via fake installation instructions.
We flagged Calude.ai as phishing. The page behavior matches a common credential-theft flow: impersonation first, urgency second, data request last. calude.ai should not be treated as a safe website. Gridinsoft gives it a 1/100 trust score,
The attacker registered the domain calude.ai, which mimics the legitimate claude.ai through a simple character transposition (swapping 'l' and 'a' to create 'cal' instead of 'cla'). This is a common typing error that users may make when att
The URL 'calude.ai' is a classic example of typosquatting via transposition. It swaps the 'l' and 'a' in the brand name 'Claude', which is a globally recognized AI platform owned by Anthropic. ... Web search results confirm that calude.ai i
Joe Sandbox analysis identifies calude.ai as typosquatting of claude.ai via 'l'/'a' transposition and links it to malware distribution via InstallFix/ClickFix tactics
Threat Detection
Antivirus results, browser warnings, isolated page observations, and the threat pattern identified in this report.
Antivirus engine results
Evidence behind this threat profile
- 1Domain name mimics claude.ai via 'l'/'a' transposition
- 214 antivirus engines flagged the URL as malicious
- 3Linked to credential-theft and InstallFix/ClickFix malware tactics
3 of 22 categories showed signals
This profile separates the site's primary threat from other patterns supported by the saved page evidence, public research, and security findings.
- 14/92 AV engines flagged as malicious or phishing (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, Chong Lua Dao, CyRadar)
- Gridinsoft flagged as phishing with 1/100 trust score and credential-theft flow pattern
- Joe Sandbox analysis confirms typosquatting of claude.ai and credential-harvesting intent
- Domain calude.ai registered to impersonate Anthropic's claude.ai via character transposition
- Joe Sandbox explicitly identifies it as mimicking the legitimate Claude AI platform
- Joe Sandbox links the domain to malware distribution via InstallFix/ClickFix tactics
- Multiple AV engines (ADMINUSLabs, Chong Lua Dao) explicitly labeled malicious
Technical Details
Identity, domain, infrastructure, and connection facts saved with this scan.
July 21, 2026 at 1:09 PM UTCIdentity
6 facts- Operator
- Missing
- On-domain email
- Not observed
- Other email
- Not observed
- Phone
- Not observed
- Postal address
- Not observed
- Social profiles
- Not observed
Domain
8 facts- Domain age
- 3 years old
- Registered
- Jul 11, 2023
- Registrar
- Dynadot Inc
- Expires
- Jul 11, 2027
- WHOIS updated
- Jun 10, 2025
- Registrant
- Dynadot Privacy Service
- Registration country
- Unavailable
- WHOIS privacy
- Enabled
Infrastructure
14 facts- HTTPS
- Valid certificate
- TLS protocol
- TLSv1.3
- Certificate issuer
- Let's Encrypt · YR1
- Certificate subject
- yen.com.au
- Certificate valid from
- Jul 7, 2026
- Certificate valid to
- Oct 5, 2026
- Network address
- 103.224.182.238
- ASN
- Unavailable
- Hosting organization
- Trellian Pty. Limited
- Country
- US
- Server
- Apache
- Site platform
- Unavailable
- IP reputation
- 0% confidence · 0 reports
- Tor exit node
- No
Connections
13 facts- Scan scope
- Domain
- Destination host
- calude.ai
- Redirects
- 0
- Cross-domain redirect
- No
- Redirect status codes
- 200
- Lookalike characters
- Not observed
- Internationalized domain
- No
- Page response
- 200
- Observation coverage
- Unavailable
- Extracted links
- Unavailable
- Unique IPs contacted
- Unavailable
- Countries contacted
- Unavailable
- Referenced domains
- 0
What to do
Do not visit or enter any information. The domain was created to impersonate the legitimate claude.ai service and has been linked to phishing and malware distribution.
If you entered a password, change it on the official service by typing its known address yourself, enable two-factor authentication, and review recent account activity. Contact your bank if you also entered payment details.
Final Verdict
Why this verdict
The domain calude.ai was registered July 12, 2023 and presents a landing page that mimics claude.ai through a simple 'l'/'a' transposition; 14 antivirus engines flagged the URL as malicious while open-web analysis links the site to credential-theft flows and InstallFix/ClickFix malware distribution.
Do not visit or enter any information. The domain was created to impersonate the legitimate claude.ai service and has been linked to phishing and malware distribution.
Key evidence
- 1Domain name mimics claude.ai via 'l'/'a' transposition
- 214 antivirus engines flagged the URL as malicious
- 3Linked to credential-theft and InstallFix/ClickFix malware tactics
Safety FAQ
Is calude.ai safe to use?+
The domain calude.ai was registered July 12, 2023 and presents a landing page that mimics claude.ai through a simple 'l'/'a' transposition; 14 antivirus engines flagged the URL as malicious while open-web analysis links the site to credential-theft flows and InstallFix/ClickFix malware distribution.
What should I do about calude.ai?+
Do not visit or enter any information. The domain was created to impersonate the legitimate claude.ai service and has been linked to phishing and malware distribution.
How old is calude.ai?+
calude.ai is 3 years old and was registered jul 12, 2023.
What if I already interacted with calude.ai?+
If you entered a password, change it on the official service by typing its known address yourself, enable two-factor authentication, and review recent account activity. Contact your bank if you also entered payment details.
When was this report updated?+
This report reflects the scan completed July 21, 2026 at 1:09 PM UTC.
User reviews & comments(0)
Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.