me-labs[.]top
“Claim Your Share of the Arbitrum Ecosystem | Up to $25,000 for Active Wallets”
me-labs.top — Contenido no disponible (HTTP 502). Suplantación de marca: Across; Tipo de estafa: Fake Airdrop. Resumen de las pruebas: VirusTotal 2/93 (alphaMountain.ai, Bfore.Ai PreCrime); PhishDestroy score 56/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain me-labs.top indicates it was actively used for a fake airdrop scam targeting users of the Across protocol, a decentralized bridging platform. The domain was registered on February 21, 2026, and resolved to the IP address 45.9.148.51, hosted by AS49447 (Nice IT Services Group Inc.) in the Netherlands. The page title, 'Claim Your Share of the Arbitrum Ecosystem | Up to $25,000 for Active Wallets,' explicitly promoted a fraudulent incentive scheme, falsely implying affiliation with Arbitrum and Across to lure victims into interacting with malicious smart contracts or disclosing wallet credentials. As of July 24, 2026, the domain has been taken offline, though it remains listed on at least one security blocklist.
Two of 93 security vendors on VirusTotal flagged the domain as malicious prior to its removal. The SSL certificate was issued by R11, a low-assurance certificate authority often associated with ephemeral phishing infrastructure. No evidence suggests the domain was ever indexed by Safe Browsing or other major reputation services, limiting retrospective visibility. Defenders should treat me-labs.top as confirmed malicious infrastructure.
Historical DNS and WHOIS records should be preserved for incident response, and any residual DNS caching or local host file entries should be purged. While the site is offline, the registration pattern—short-lived domain with a crypto-themed lure—aligns with known phishing campaigns targeting DeFi users. Monitoring for re-registration or reuse of the same IP or ASN may help detect related threats. The exact content of the phishing page remains unanalyzed; however, the combination of brand impersonation, airdrop lure, and hosting on bulletproof infrastructure warrants blocking all associated indicators.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.