MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für airdrops-sonic.pages.dev
airdrops-sonic[.]
The domain airdrops-sonic.pages.dev is a cryptocurrency phishing site designed to function as a crypto drainer, a type of scam that automatically siphons digital assets from connected wallets.
- VirusTotal
- 2/93
- Blocklists
- 1 · ScamSniffer
- Verfügbarkeit
- Erreichbar · Zugang eingeschränkt · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
airdrops-sonic.pages.dev — Erreichbar · Zugang eingeschränkt (HTTP 403). Betrugstyp: Airdrop Scam. Zusammenfassung der Beweislage: VirusTotal 2/93 (Gridinsoft, Trustwave); Google Safe Browsing flagged; 1 external blocklist match (ScamSniffer); PhishDestroy score 80/100. Registrar: Cloudflare.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
The domain airdrops-sonic.pages.dev is a cryptocurrency phishing site designed to function as a crypto drainer, a type of scam that automatically siphons digital assets from connected wallets. No legitimate brand or drainer kit was identified in this case. The site is currently taken offline, but its prior activity posed an elevated risk to users who may have interacted with it.
Technical indicators confirm the malicious nature of airdrops-sonic.pages.dev. The domain was flagged by 2 of 95 VirusTotal security vendors, including Gridinsoft (trust score 0/100) and Trustwave, and was listed on Google Safe Browsing for 'SOCIAL_ENGINEERING'. It appeared on 2 security blocklists (PhishDestroy and ScamSniffer) and was registered through Cloudflare, Inc. on December 06, 2024. The domain resolved to IP address 172.66.47.43 (US, AS13335 Cloudflare, Inc.) and used an SSL certificate issued by Google Trust Services / WE1. The observed page title was 'Suspected phishing site | Cloudflare', and the site returned an HTTP 403 status. Nameservers were sara.ns.cloudflare.com and denver.ns.cloudflare.com, and technologies detected included HSTS, Cloudflare, and HTTP/3.
Users who connected a wallet to airdrops-sonic.pages.dev should immediately revoke all token approvals using a tool like revoke.cash or Etherscan's token approval checker. Funds should be moved to a new, secure wallet to prevent further unauthorized transactions. If credentials or personal information were entered, passwords should be changed, and two-factor authentication enabled on all accounts. The domain can be reported to Google Safe Browsing, PhishTank, or the relevant wallet provider for further investigation.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Forensische Erkenntnisse
Technologien · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of airdrops-sonic.pages.dev · checked Apr 13, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.