megarewardpool[.]xyz
megarewardpool.xyz — No verificado. Tipo de estafa: Fake Airdrop. Resumen de las pruebas: VirusTotal 5/93 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet, SOCRadar); Spamhaus DBL_PHISH; PhishDestroy score 65/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of megarewardpool.xyz indicates that the domain was registered on 21 February 2026 through NiceNIC International Group Co., Limited. The site was hosted behind Cloudflare, using the IP address 104.21.81.112 which belongs to AS13335 (Cloudflare, Inc.) and is geolocated in the United States. DNS resolution points to the Cloudflare nameservers buck.ns.cloudflare.com and tara.ns.cloudflare.com, and the TLS certificate presented is issued by Google Trust Services under the WE1 profile, confirming a valid HTTPS endpoint. The page title returned during the brief live check was "Just a moment…", and automated fingerprinting identified Cloudflare Browser Insights, HTTP/3, and generic Cloudflare services as the underlying technologies. Threat intelligence classifies the domain as a "Fake Airdrop" scam, a variant of generic phishing that typically lures victims with promises of cryptocurrency rewards.
VirusTotal recorded five detections out of ninety‑three scanners, and the domain appears on a single external blocklist, where it is listed by PhishDestroy. No additional public blocklists or reputation services were observed in the supplied data. The domain’s current status is offline, which limits real‑time observation of malicious payloads or credential‑harvesting forms. Consequently, the exact content and any post‑delivery behavior remain unknown. However, the combination of a recent registration, Cloudflare‑based hosting, a Google‑signed certificate, and the presence on a phishing‑focused blocklist aligns with known infrastructure patterns used for short‑lived phishing campaigns targeting cryptocurrency users.
Defenders should add the domain and its resolved IP address to network‑level deny lists and monitor DNS queries for the associated Cloudflare nameservers. Email gateways should be configured to block messages referencing airdrop incentives that reference the domain or similar patterns.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-15 03:09:57 UTC
Tecnologías · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of megarewardpool.xyz · checked Apr 11, 2026
Datos y informes externos
PD-20260214-F9C691 Recipient: abuse@nicenic.net ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.