MALICIOUS — CRITICAL
Analyse phishing et sécurité de pira.pages.dev
pira[.]
This domain, pira.pages.dev, is flagged for brand impersonation targeting cryptocurrency users through a fraudulent airdrop scheme.
- VirusTotal
- 4/91
- Blocklists
- 1 · ScamSniffer
- Disponibilité
- Dernier actif connu · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
pira.pages.dev — Dernier actif connu (HTTP 200). Type d'arnaque : Fake Airdrop. Résumé des preuves: VirusTotal 4/91 (ADMINUSLabs, BitDefender, G-Data, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 76/100. Bureau d’enregistrement: Cloudflare Pages.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
This domain, pira.pages.dev, is flagged for brand impersonation targeting cryptocurrency users through a fraudulent airdrop scheme. Analysis indicates the site mimics legitimate airdrop promotions to deceive victims into connecting wallets or disclosing private keys, likely deploying a crypto drainer script upon interaction. The page title explicitly displays 'Airdrop,' a common lure in such scams, and no legitimate brand association is identified, reinforcing its malicious intent.
Technical indicators confirm the domain's high-risk status. It resolves to IP 188.114.96.3, registered through Cloudflare Pages on May 17, 2026, with an SSL certificate issued by Google Trust Services (WE1). VirusTotal detection shows 3/95 security vendors flagging the domain as malicious. The infrastructure is hosted in Canada under Cloudflare, Inc., and the domain appears on two security blocklists. No entries are present in Google Safe Browsing at the time of analysis, but the low detection rate may reflect evasion tactics or recent deployment.
The domain remains active, with no takedown or sinkholing observed. Response actions should include immediate blocklisting at the DNS and network levels, as well as wallet address monitoring for associated drainer activity. Users are advised to verify airdrop legitimacy through official project channels only, avoid connecting wallets to unverified sites, and employ browser-based transaction simulators to detect malicious scripts. Given the persistent activity and low detection rate, heightened vigilance is warranted for similar impersonation schemes leveraging Cloudflare Pages infrastructure.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Couverture des données12 recorded checks
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externesIndependent lookups and source reports
“Malicious Website”
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.