airdrop-brevis[.]network
“Brevis Airdrop”
The domain airdrop-brevis.network was registered on February 21, 2026 and is currently listed as offline. DNS resolution points to IP address 172.67.128.67, which belongs to Cloudflare, Inc. (AS13335) and is geolocated to the United States. The site presents a page title of "Brevis Airdrop," matching the known crypto‑drainer scam type. An SSL certificate identified as WE1 is associated with the domain, indicating use of HTTPS despite the underlying malicious intent.
Threat intelligence shows the domain appears on five independent security blocklists and has been flagged by the following vendors: PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. VirusTotal analysis reports that three out of ninety‑three scanning engines flagged the domain, reinforcing the malicious assessment. The combination of Cloudflare hosting, a dedicated SSL certificate, and the presence of a known "Airdrop Scam" phishing kit suggests a deliberate attempt to lure cryptocurrency users into a fake airdrop claim, likely to harvest private keys or redirect funds.
While the site is currently taken offline, the elevated risk rating remains justified because the infrastructure (IP and hosting provider) can be reused for future campaigns, and the domain name itself may be leveraged in social engineering messages. Defenders should proactively block the domain and its resolving IP at perimeter firewalls and DNS filtering solutions, add the listed blocklist identifiers to threat‑intelligence feeds, and monitor Cloudflare‑hosted assets for similar naming patterns. Continuous observation of VirusTotal and other sandbox results is advised to capture any re‑activation, and incident response teams should educate users about the "Brevis Airdrop" lure to reduce exposure to this crypto drainer vector.
Threat Response Pipeline
Public Blocklist Status
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive