dapp-reward[.]pages[.]dev
Phishing- und Sicherheitsprüfung für dapp-reward.pages.dev
“ordialsynprotocol”
dapp-reward.pages.dev — Letzter bekanntermaßen aktiv (HTTP 200). Betrugstyp: Fake Airdrop. Zusammenfassung der Beweislage: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 100/100. Registrar: Cloudflare.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, dapp-reward.pages.dev, is identified as a high-risk phishing site impersonating a cryptocurrency protocol under the name 'ordialsynprotocol'. Analysis indicates it functions as a wallet drainer, designed to harvest private keys, seed phrases, and sensitive credentials from unsuspecting users attempting to interact with decentralized applications. The site mimics legitimate Ordinals or synthetic asset protocols, likely exploiting recent trends in Bitcoin layer-2 solutions to deceive victims into connecting compromised wallets. Infrastructure analysis reveals multiple technical indicators of malicious activity. The domain is registered through Cloudflare, Inc., with a creation date of July 03, 2024, and resolves to the IPv6 address 2606:4700:3030::6815:5001, hosted on Cloudflare’s network (AS13335). It is flagged by 14 out of 95 security vendors on VirusTotal, and appears on three independent security blocklists. The SSL certificate is issued by Google Trust Services (WE1), a common characteristic of both legitimate and malicious Cloudflare-hosted sites. No Google Safe Browsing (GSB) detection was explicitly noted, but the domain remains actively blocked by multiple threat intelligence feeds. As of the latest assessment, dapp-reward.pages.dev remains active and continues to pose a significant risk to users. The site is still serving malicious content, and no takedown or suspension has been observed. Users are strongly advised to avoid interaction with the domain, and wallet software should enforce hard blocks on any connection attempts. Organizations are recommended to update internal blocklists with the domain and associated IP, and monitor for related infrastructure reuse under similar naming conventions. The combination of recent registration, Cloudflare hosting, and confirmed drainer functionality underscores the need for heightened vigilance in decentralized finance environments.
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Forensische Erkenntnisse
Technologien · 5 identified
Fast CDN for everything on npm — serves raw files from npm packages.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of dapp-reward.pages.dev · checked Mar 2, 2026
Nachweise und externe Berichte
“AngelDrain”
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt