ellx[.]pages[.]dev
ellx.pages.dev की फ़िशिंग और सुरक्षा जाँच
“ELIXIR TOKEN AIRDROP”
ellx.pages.dev — पहुंच योग्य · पहुंच प्रतिबंधित (HTTP 403). घोटाले का प्रकार: Airdrop Scam. साक्ष्य सारांश: VirusTotal 12/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 86/100. रजिस्ट्रार: Cloudflare.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Ellx.pages.dev was observed hosting a page titled “ELIXIR TOKEN AIRDROP”. The site resolves to 172.66.44.75, an address owned by Cloudflare (AS13335) located in the United States. Registration data shows the domain was created on 23 April 2024 and is serviced by the Cloudflare nameservers renan.ns.cloudflare.com and sneh.ns.cloudflare.com. The HTTP response returned a 403 status code and the server advertised HSTS, HTTP/3 and the Cloudflare CDN, confirming the use of Cloudflare’s edge infrastructure. Security‑vendor aggregators have flagged the domain.
VirusTotal reports 12 of 94 scanned engines marking the host as malicious, and the domain appears on three independent blocklists. It has been specifically listed by PhishDestroy, MetaMask and SEAL as a “Fake Airdrop” campaign, matching the “Airdrop Scam” phishing kit identified in the payload. Gridinsoft assigned a trust score of 0 / 100, indicating a high confidence of malicious intent. The current operational status is offline, with the site returning HTTP 403, but historical evidence confirms it was actively serving the fraudulent airdrop page before takedown. The evidence points to a classic cryptocurrency‑airdrop deception, leveraging the recognizable “Elixir Token” name to lure victims into submitting private keys or wallet credentials.
While the page content itself has not been captured, the combination of the page title, kit attribution, and multiple vendor detections provides sufficient confidence to classify the domain as a high‑risk phishing vector. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any re‑registration of similar sub‑domains under the same registrar, and enforce user awareness training that warns against unsolicited token airdrop offers. Threat‑intel feeds should be updated with the domain, its IP address, and associated blocklist identifiers to prevent future exposure.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of ellx.pages.dev · checked Mar 16, 2026
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।