airdrop-rewards.pages.dev
“Suspected Phishing | Cloudflare”
Evidence Summary
Analysis of airdrop-rewards.pages.dev shows that the domain was registered on June 01, 2026 via Cloudflare Pages and resolves to the IPv4 address 188.114.96.3. The site is currently classified as a crypto drainer, with a high risk rating and an active status. Independent scanning on VirusTotal returned 14 positive detections out of 91 submitted security engines, indicating that multiple antivirus and URL‑reputation products have identified malicious behavior associated with the domain. The domain also appears on four external blocklists, and it has been explicitly blocked by commercial protection services including PhishDestroy, MetaMask, ScamSniffer, and SEAL.
These overlapping signals suggest a concerted effort to distribute cryptocurrency‑draining payloads or lure victims into authorizing malicious transactions. The infrastructure choice of Cloudflare Pages provides legitimate‑looking hosting while concealing the true origin of the malicious content, and the public IP address 188.114.96.3 is shared among other abuse reports, which complicates attribution. No additional evidence such as SSL certificate details, HTTP response codes, or page titles is presently available, limiting the depth of fingerprinting.
Defenders should add the domain and its resolved IP to deny‑list rules, monitor for any outbound connections to the address, and enforce multi‑factor authentication and transaction‑confirmation prompts for wallet‑related activities. Continuous re‑inspection of the domain on VirusTotal and blocklist feeds is recommended, as the threat actor may alter hosting or deploy new tactics. Organizations that handle cryptocurrency transactions should treat any request originating from this domain as malicious and block it at the network perimeter.
Network Security Intelligence
Forensic History & Detection Timeline
-
Domain Status Transition Jul 29, 2026 · 12:49 UTCDomain state transitioned from alive to dead.
-
Threat First Observed Jul 29, 2026 · 09:22 UTCDomain ingestion complete. Initial state is marked as unknown pointing to IP
188.114.96.3.
Threat Response Pipeline
Public Blocklist Status
Technologies · 3 identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of airdrop-rewards.pages.dev · checked Jul 29, 2026
Community reports
Reported by 1 community member, first seen Jun 10, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive