allocation-xrpl[.]org
“The Biggest XRP Airdrop”
Résumé des preuves
Analysis indicates that allocation-xrpl.org was registered on 21 February 2026 through NiceNIC International Group Co., Limited and resolves to the Cloudflare address 188.114.97.3 (AS13335, United States). The domain is currently taken offline, but historical records show it served a page titled “The Biggest XRP Airdrop”. The page title, together with the classification of the kit as “Airdrop Scam”, points to a cryptocurrency‑focused impersonation campaign that targets the Ledger brand. The site was listed on a security blocklist, flagged by Google Safe Browsing for social engineering, and appears in one AlienVault OTX pulse. VirusTotal scans returned eight positive detections out of ninety‑three submitted samples, confirming that multiple anti‑malware engines consider the domain malicious.
Cloudflare nameservers ara.ns.cloudflare.com and wilson.ns.cloudflare.com were observed, and no TLS certificate was presented, indicating that the site operated over plain HTTP. Gridinsoft assigned a trust score of zero out of one hundred, reinforcing the low credibility assessment. PhishDestroy has actively blocked the domain. The combination of a brand‑specific impersonation tag, the airdrop‑related kit, and the presence of multiple independent detections suggests a coordinated attempt to lure Ledger users into a crypto‑airdrop scam.
Uncertainty remains regarding the current activity of the infrastructure, as the domain is offline and no recent HTTP response can be observed. Defenders should add the domain to internal blocklists, monitor the associated IP address for any re‑use, and enforce strict outbound filtering for URLs containing “airdrop” or references to Ledger. Email gateways should be tuned to flag messages that reference “XRP airdrop” or similar phrasing, especially when paired with Ledger branding.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Preuves du résultat enregistrées
Résultat et attribution du retrait
- Résultat
held- Disponibilité
unreachable- Cause
registrar_client_hold- Acteur
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mécanisme
client_hold- Confiance
- 95%
- Première observation
- Dernière observation
Indisponibilité estimée
Délai avant indisponibilité: 0 hSHA-256 de la preuve 54fa96868018
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
Disponibilité
Première valeur enregistrée : DNS inactif
f93a11f87e4d -
Disponibilité
DNS inactif → Inconnu
638c440c2b26 -
Disponibilité
Inconnu → Inactif
c9d1fb2414b7 -
Disponibilité
Inactif → DNS inactif
492be6c9a130 -
Disponibilité
DNS inactif → Retenu
6f38b01085df -
Disponibilité
Retenu → DNS inactif
f52d526b76a1 -
Disponibilité
DNS inactif → Inconnu
d1ee947a454f -
Disponibilité
Inconnu → Retenu
ae56bf1c0872 -
Disponibilité
Retenu → Inconnu
2b07bfc8ce96
Tout afficher (8)
-
Disponibilité
Inconnu → DNS inactif
6dfe9145995c -
Disponibilité
DNS inactif → Retenu
d66d91141658 -
Disponibilité
Retenu → DNS inactif
641ed81dc4d5 -
Disponibilité
DNS inactif → Inconnu
5612214f6cae -
Disponibilité
Inconnu → Retenu
6d7250b64a57 -
Disponibilité
Retenu → Inconnu
bb0f084acd23 -
Disponibilité
Inconnu → DNS inactif
d0b7046e8c2f -
Disponibilité
DNS inactif → Retenu
54fa96868018
Signalements communautaires
Signalé par 1 membre de la communauté ; première observation le 24/01/2026
- Signalements enregistrés
- 1
- URL signalées uniques
- 1
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse forensique
Analyse VirusTotal
Domaines ressemblants
151 domaines ressemblants enregistrés
Tout afficher (88)
100 affichés sur 151
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif