pi-airdrop[.]ct[.]ws
“Pi Network – Get your free pi reward”
pi-airdrop.ct.ws — No verificado. Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 4/91 (alphaMountain.ai, Chong Lua Dao, Gridinsoft, LevelBlue); Spamhaus DBL_PHISH; PhishDestroy score 71/100. Registrador: Namecheap.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of pi‑airdrop.ct.ws indicates a high‑risk cryptocurrency drainer operation. The site presents the page title “Pi Network – Get your free pi reward,” which is commonly used in fraudulent campaigns targeting users of the Pi Network project. The domain is currently active and classified as a crypto‑drainer, confirming its intent to lure victims into transferring digital assets.
Infrastructure analysis reveals the site is hosted on a server located in the United Kingdom, identified by IP address 185.27.134.34 belonging to AS34119 Wildcard UK Limited. The domain resolves through the Byet.org name server cluster (ns1.byet.org, ns2.byet.org, ns3.byet.org, ns4.byet.org, ns5.byet.org). The web stack consists of WordPress powered by PHP and MySQL, front‑ended by Nginx/OpenResty and enriched with jQuery, jQuery Migrate, and Font Awesome libraries. SSL is provided by ZeroSSL ECC Domain Secure Site CA, indicating a publicly available free certificate.
Reputation signals show a zero‑point trust rating from Gridinsoft, and five out of ninety‑five VirusTotal scanners have flagged the domain as malicious. The site is listed on a single security blocklist and has been actively blocked by the PhishDestroy service. HTTP requests return a 200 status code, confirming the site is serving content without immediate disruption.
Defenders should prioritize immediate containment by adding pi‑airdrop.ct.ws to network blocklists and DNS filtering rules. Continuous monitoring of the associated IP address and its ASN is advised, as the hosting provider may be leveraged for additional malicious domains. Incident response teams should also audit any inbound traffic that references the “Pi Network” reward phrasing, and consider sinkholing the domain to disrupt the campaign’s infrastructure.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 8 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Icon font library.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of pi-airdrop.ct.ws · checked Mar 2, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.