qantasrewards[.]8888259[.]com
“Welcome to nginx!”
qantasrewards.8888259.com — Contenido no disponible (HTTP 502). Suplantación de marca: ["x.com"]; Tipo de estafa: Fake Airdrop. Resumen de las pruebas: VirusTotal 15/93 (BitDefender, Cluster25, CRDF, CyRadar, Fortinet); PhishDestroy score 95/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain qantasrewards.8888259.com was registered on 21 February 2026 and is presently taken offline. DNS resolution points to the IP address 172.67.142.98, which belongs to Cloudflare, Inc. (ASN 13335) and is geolocated in the United States. The web server returns the default “Welcome to nginx!” title, indicating that no custom landing page was observed at the time of analysis. The SSL certificate presented is identified as “WE1”, a generic certificate that does not provide brand‑specific validation. VirusTotal has recorded 15 detections out of 93 scanning engines, confirming that a notable portion of security vendors classify the domain as malicious.
The site is listed on a single security blocklist and is actively blocked by the PhishDestroy service. The intelligence tag assigns the scam type “Fake Airdrop”, suggesting that the domain was used to lure victims with a fraudulent cryptocurrency airdrop promise. Evidence points to a typical phishing infrastructure: use of Cloudflare’s CDN to hide the origin server, a generic nginx banner, and a low‑reputation SSL certificate. However, the absence of additional data such as Safe Browsing verdicts, OTX mentions, or registrar information limits a full attribution of the threat actor. The current offline status prevents immediate content inspection, and the exact phishing payload or credential‑harvesting mechanism remains unknown.
Defenders should add qantasrewards.8888259.com to internal blocklists and ensure that any outbound connections to 172.67.142.98 are denied. Monitoring of Cloudflare‑related IP ranges for similar patterns is advisable, as is reviewing any user‑reported attempts that reference a “airdrop” promise tied to the Qantas brand. Given the 15 VirusTotal detections, endpoint protection solutions that reference VirusTotal scores should flag the domain as malicious.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.