heaven-airdrop[.]website
heaven-airdrop.website — Contenido no disponible. Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 3/93 (alphaMountain.ai, Fortinet, G-Data); 4 external blocklist matches; PhishDestroy score 82/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain heaven-airdrop.website was registered on February 21, 2026 and is currently taken offline. Infrastructure analysis shows it resolved to the IP address 188.114.96.3, which belongs to the Cloudflare network (AS13335) and is geolocated in the United States. The SSL certificate presented for the host is identified as WE1, indicating the use of a potentially self‑signed or low‑reputation certificate. Reputation services provide a consistent picture of malicious activity: Gridinsoft assigns a trust score of 0 out of 100, effectively marking the site as completely untrustworthy.
VirusTotal scans report that three of ninety‑three security vendors flagged the domain, confirming that at least a subset of commercial engines recognize it as suspicious. The domain appears on five independent blocklists—PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura—each of which classifies it under a crypto‑drainer scam type. No page title or additional content analysis is available, and the site’s HTTP response has not been captured because the service is offline. The combination of a recent registration date, Cloudflare‑hosted IP, low trust score, multiple blocklist listings, and partial vendor detections strongly suggests that the domain was used to lure cryptocurrency owners into transferring assets to attacker‑controlled wallets.
Defenders should continue to block the IP 188.114.96.3 at network perimeters, add heaven‑airdrop.website to DNS sink‑hole lists, and monitor outbound traffic for attempts to resolve or contact this domain. Given the Cloudflare front‑end, attackers may shift to alternative IPs within the same ASN; therefore, security teams should apply ASN‑wide filtering for AS13335 when suspicious crypto‑related traffic is observed. Ongoing threat‑intel feeds should be consulted for any re‑appearance of the domain or related indicators, and incident response playbooks should be updated to include this specific crypto‑drainer signature.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.