MALICIOUS — CRITICAL
megauploads[.]pages[.]dev
PhishDestroy identifies megauploads.pages.dev as an active crypto drainer campaign impersonating MegaUpload.
- VirusTotal
- 2/91
- Blocklists
- No stored match
- التوفر
- آخر نشاط معروف · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
megauploads.pages.dev — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: TikTok; نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 2/91 (alphaMountain.ai, Fortinet); URLQuery 1 alert; PhishDestroy score 71/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
megauploads.pages.dev Crypto Drainer Campaign Active
PhishDestroy identifies megauploads.pages.dev as an active crypto drainer impersonating MegaUpload. Flagged by 0 of 95 VirusTotal vendors.
PhishDestroy identifies megauploads.pages.dev as an active crypto drainer campaign impersonating MegaUpload. This domain is currently hosting malicious content designed to deceive users into connecting crypto wallets or entering private keys, resulting in fund theft.
This domain was flagged by 0 of 95 VirusTotal vendors, indicating it remains undetected by most antivirus engines as of the latest scan. Registered through Cloudflare, Inc., megauploads.pages.dev resolves to IP 172.66.47.158 and holds a valid SSL certificate issued by Google Trust Services. Despite its low detection rate, the domain’s infrastructure and certificate suggest a deliberate effort to appear legitimate while delivering malicious payloads.
Given the active status of this campaign and its low detection rate, users should treat megauploads.pages.dev as a high-risk domain. Immediate action includes blocking the domain at the network and endpoint levels, revoking any connected wallet permissions associated with interactions on this domain, and reporting the domain to threat intelligence platforms. Organizations are advised to monitor for related hashes, IPs, and domains to prevent lateral movement within networks. Proactive threat hunting for similar infrastructure patterns is strongly recommended to mitigate potential crypto theft.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | nsfw-tiktok.pages.dev//0709(1).gif |
malware | Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.