foru-airdrop-test[.]pages[.]dev
“Vite + React + TS”
Resumen de las pruebas
Analysis of foru-airdrop-test.pages.dev shows a newly created infrastructure that was used for a fake airdrop crypto‑drainer campaign. The domain was registered on February 21, 2026 through Cloudflare, Inc., and its DNS resolves to the Cloudflare edge address 104.21.96.1, which is located in the United States under ASN 13335 (Cloudflare, Inc.). No SSL certificate is presented, indicating that the site served HTTP only or that TLS termination was not configured on the origin. The page title returned by the server is "Vite + React + TS," suggesting the site was built with a modern JavaScript stack but providing no further clue about the scam content.
VirusTotal recorded a single positive detection out of 93 scanning engines, and the domain appears on one external security blocklist. PhishDestroy has taken the domain offline, and its current status is listed as offline with an elevated risk rating. The campaign is classified as a fake airdrop, a subtype of crypto drainer scams that attempt to trick victims into sending cryptocurrency to an attacker‑controlled address. Defenders should block the domain and its associated IP address at perimeter firewalls and DNS filtering solutions, monitor for any residual traffic to 104.21.96.1, and add the domain to internal blocklists.
Because the site is already taken down, the immediate threat is reduced, but the registration pattern—using Cloudflare’s free registration and a generic page title—may be reused in future campaigns. Continuous observation of new domains registered through Cloudflare and rapid correlation with detection alerts can help mitigate repeat abuse. Organizations should also educate users about unsolicited airdrop offers and advise verification of any crypto‑transfer requests before execution.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.