MALICIOUS — CRITICAL
ARBS Airdrop Phishing Domain: arbswaps.app
arbswaps[.]
This domain is flagged as a high-risk generic phishing threat, specifically a fake airdrop scam targeting cryptocurrency users.
- VirusTotal
- 6/91
- Blocklists
- 2 · MetaMask, SEAL
- उपलब्धता
- पहुंच योग्य · पहुंच प्रतिबंधित · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
arbswaps.app — पहुंच योग्य · पहुंच प्रतिबंधित (HTTP 403). घोटाले का प्रकार: Fake Airdrop. साक्ष्य सारांश: VirusTotal 6/91 (alphaMountain.ai, CRDF, Ermes, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
This domain is flagged as a high-risk generic phishing threat, specifically a fake airdrop scam targeting cryptocurrency users. The domain arbswaps.app was registered on April 10, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, and resolves to IP 188.114.96.3 hosted by Cloudflare, Inc. in Canada. The page title is $ARBS Airdrop, and the phishing kit used is categorized as Airdrop Scam. Infrastructure analysis shows nameservers are dawn.ns.cloudflare.com and titan.ns.cloudflare.com, with an SSL certificate issued by Let's Encrypt. The domain is currently active and returns an HTTP 403 status, indicating access is blocked or restricted. Threat intelligence from VirusTotal shows 3 of 94 security vendors flagging this domain as malicious, and it appears on 3 security blocklists including PhishDestroy, MetaMask, and SEAL. AlienVault OTX confirms presence in 1 threat intelligence pulse. The Gridinsoft trust score is 0/100. Defenders should block this domain at the DNS and email gateway levels, monitor for related subdomains or IPs, and warn users about unsolicited airdrop offers. The exact page content beyond the title has not been analyzed visually, but the phishing kit classification strongly indicates a credential or wallet theft scheme. Uncertainties include the full scope of the attack infrastructure and whether it targets specific blockchain wallets.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
डेटा कवरेज12 recorded checks
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:42:50 UTC
वायरसटोटल विश्लेषण
साइट कॉन्फ़िगरेशन विश्लेषण
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।