foru-airdrop-test[.]pages[.]dev
“Vite + React + TS”
Riepilogo delle prove
Analysis of foru-airdrop-test.pages.dev shows a newly created infrastructure that was used for a fake airdrop crypto‑drainer campaign. The domain was registered on February 21, 2026 through Cloudflare, Inc., and its DNS resolves to the Cloudflare edge address 104.21.96.1, which is located in the United States under ASN 13335 (Cloudflare, Inc.). No SSL certificate is presented, indicating that the site served HTTP only or that TLS termination was not configured on the origin. The page title returned by the server is "Vite + React + TS," suggesting the site was built with a modern JavaScript stack but providing no further clue about the scam content.
VirusTotal recorded a single positive detection out of 93 scanning engines, and the domain appears on one external security blocklist. PhishDestroy has taken the domain offline, and its current status is listed as offline with an elevated risk rating. The campaign is classified as a fake airdrop, a subtype of crypto drainer scams that attempt to trick victims into sending cryptocurrency to an attacker‑controlled address. Defenders should block the domain and its associated IP address at perimeter firewalls and DNS filtering solutions, monitor for any residual traffic to 104.21.96.1, and add the domain to internal blocklists.
Because the site is already taken down, the immediate threat is reduced, but the registration pattern—using Cloudflare’s free registration and a generic page title—may be reused in future campaigns. Continuous observation of new domains registered through Cloudflare and rapid correlation with detection alerts can help mitigate repeat abuse. Organizations should also educate users about unsolicited airdrop offers and advise verification of any crypto‑transfer requests before execution.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo