eth-rebate[.]pages[.]dev
Analyse phishing et sécurité de eth-rebate.pages.dev
“2025/2026 Phase 1 ETH Community Airdrop”
eth-rebate.pages.dev — Dernier actif connu (HTTP 200). Type d'arnaque : Fake Airdrop. Résumé des preuves: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Fortinet); PhishDestroy score 96/100. Bureau d’enregistrement: Cloudflare Pages.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, eth-rebate.pages.dev, is actively engaged in brand impersonation targeting cryptocurrency users through a fraudulent airdrop scheme. The page title, '2025/2026 Phase 1 ETH Community Airdrop,' explicitly mimics legitimate Ethereum community initiatives, attempting to deceive users into interacting with malicious smart contracts or disclosing wallet credentials. No direct evidence of a crypto drainer kit has been observed, though the infrastructure aligns with common airdrop scam patterns designed to exfiltrate assets or harvest sensitive data. Analysis indicates the domain was registered through Cloudflare Pages on May 6, 2026, and currently resolves to the IP address 188.114.96.3, hosted under Cloudflare, Inc. in Canada. Detection metrics reveal minimal exposure at present: the domain appears on only one security blocklist, and VirusTotal reports a 0/95 detection rate across its scanning engines. The SSL certificate, issued by Google Trust Services (WE1), provides a veneer of legitimacy but does not mitigate the underlying fraudulent intent. No entries have been recorded in Google Safe Browsing databases as of this assessment. The domain remains operational, posing an ongoing risk to users unaware of the impersonation tactic. Response actions have been limited to partial blocklisting, with no takedown or sinkholing observed. The low detection rate suggests the campaign may still be in an early or evasive phase, potentially targeting niche communities. Users are advised to verify airdrop legitimacy through official Ethereum channels and employ wallet isolation when interacting with unverified smart contracts. Continuous monitoring of this infrastructure is recommended to assess evolving threats.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif