airdrop-888[.]xyz
“打开 TP 钱包”
airdrop-888.xyz — Non vérifié. Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); PhishDestroy score 94/100. Bureau d’enregistrement: Go Daddy.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, airdrop-888.xyz, is actively flagged as a high-risk phishing site targeting users through an airdrop scam. Registered on November 14, 2025, via Go Daddy, LLC, the domain resolves to the IP address 185.199.109.153, a host commonly associated with content delivery networks. The page title, '打开 TP 钱包' (translated as 'Open TP Wallet'), suggests an attempt to deceive users into interacting with a cryptocurrency wallet, likely as part of a fraudulent airdrop scheme. Analysis indicates the site is designed to harvest credentials or manipulate victims into transferring assets under false pretenses. Infrastructure analysis reveals the use of Varnish, GitHub Pages, HSTS, and Fastly, which are legitimate technologies but frequently leveraged in phishing campaigns to evade detection or improve performance. The SSL certificate is issued by GoDaddy.com, a common certificate authority, which does not mitigate the malicious intent of the domain. The domain is currently active and has been flagged by 11 out of 95 security vendors on VirusTotal, alongside listings in 23 threat intelligence pulses on AlienVault OTX. It also appears on two security blocklists, reinforcing its classification as a confirmed threat. Defenders should treat this domain as hostile and prioritize blocking it at the network level. The domain’s low trust scores (1/100 on Scamadviser and 0/100 on Gridinsoft) further corroborate its malicious nature. While the exact mechanics of the scam remain unconfirmed due to the absence of deeper forensic analysis, the combination of brand impersonation, cryptocurrency wallet references, and active security vendor detections provides sufficient evidence for immediate mitigation. Monitoring for related domains or IPs, particularly those sharing the same hosting infrastructure, is recommended to preemptively disrupt similar campaigns.
Signaux de sécurité
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 4 identified
Static site hosting provided free by GitHub.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Edge cloud platform — CDN, security and edge compute.
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of airdrop-888.xyz · checked Mar 2, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif