MALICIOUS — HIGH
Analyse phishing et sécurité de eligible-sullend.fun
eligible-sullend[.]
Analysis of the domain eligible-sullend.fun confirms its classification as a fraudulent phishing site targeting Discord users through a fake airdrop scheme.
- VirusTotal
- 1/93
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilité
- Contenu indisponible · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
eligible-sullend.fun — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Discord; Type d'arnaque : Fake Airdrop. Résumé des preuves: VirusTotal 1/93 (SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Bureau d’enregistrement: PDR.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
Analysis of the domain eligible-sullend.fun confirms its classification as a fraudulent phishing site targeting Discord users through a fake airdrop scheme. The domain was registered on February 27, 2026, via PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently associated with abusive registrations. Infrastructure analysis reveals the domain resolves to IP address 172.67.199.112, hosted on Cloudflare's network (AS13335), and utilizes Cloudflare nameservers becky.ns.cloudflare.com and keenan.ns.cloudflare.com. The site's page title, 'Phase 2 Distribution,' aligns with known patterns of airdrop scams, where victims are lured into claiming non-existent rewards. Detection data indicates the domain is flagged by three security blocklists, including PhishDestroy, MetaMask, and SEAL, confirming its malicious status.
Gridinsoft assigns a trust score of 0/100, further validating its high-risk nature. While the domain is currently offline, its prior activity and infrastructure remain relevant for defensive measures. Notably, the domain lacks an SSL certificate, a common red flag in phishing campaigns. VirusTotal records a single detection from 93 security vendors, though this limited visibility does not diminish the confirmed threat.
Defenders should prioritize blocking this domain and its associated IP across security gateways. Given the use of Cloudflare, additional scrutiny of domains sharing the same nameservers or IP range may uncover related malicious activity. The absence of SSL and the domain's short lifespan (registered less than five months prior to the report date) are consistent with disposable phishing infrastructure. Organizations are advised to monitor for similar domains registered through PDR Ltd. and leveraging Cloudflare hosting, as these attributes are recurrent in brand impersonation campaigns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Couverture des données12 recorded checks
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Données factuelles et rapports externesIndependent lookups and source reports
PD-20260227-D9CBB8 Recipient: abuse@publicdomainregistry.com Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.