pira[.]pages[.]dev
Verifica phishing e sicurezza per pira.pages.dev
“Airdrop”
pira.pages.dev — Ultimo attivo conosciuto (HTTP 200). Tipo di truffa: Fake Airdrop. Riepilogo delle prove: VirusTotal 4/91 (ADMINUSLabs, BitDefender, G-Data, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 76/100. Registrar: Cloudflare Pages.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
This domain, pira.pages.dev, is flagged for brand impersonation targeting cryptocurrency users through a fraudulent airdrop scheme. Analysis indicates the site mimics legitimate airdrop promotions to deceive victims into connecting wallets or disclosing private keys, likely deploying a crypto drainer script upon interaction. The page title explicitly displays 'Airdrop,' a common lure in such scams, and no legitimate brand association is identified, reinforcing its malicious intent.
Technical indicators confirm the domain's high-risk status. It resolves to IP 188.114.96.3, registered through Cloudflare Pages on May 17, 2026, with an SSL certificate issued by Google Trust Services (WE1). VirusTotal detection shows 3/95 security vendors flagging the domain as malicious. The infrastructure is hosted in Canada under Cloudflare, Inc., and the domain appears on two security blocklists. No entries are present in Google Safe Browsing at the time of analysis, but the low detection rate may reflect evasion tactics or recent deployment.
The domain remains active, with no takedown or sinkholing observed. Response actions should include immediate blocklisting at the DNS and network levels, as well as wallet address monitoring for associated drainer activity. Users are advised to verify airdrop legitimacy through official project channels only, avoid connecting wallets to unverified sites, and employ browser-based transaction simulators to detect malicious scripts. Given the persistent activity and low detection rate, heightened vigilance is warranted for similar impersonation schemes leveraging Cloudflare Pages infrastructure.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
“Malicious Website”
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.