MALICIOUS — HIGH
ttcoi[.]pages[.]dev
This domain operates as a cryptocurrency airdrop scam designed to deceive users into believing they can claim legitimate $TC tokens from TTcoin.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Disponibilità
- Ultimo attivo conosciuto · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
ttcoi.pages.dev — Ultimo attivo conosciuto (HTTP 200). Tipo di truffa: Fake Airdrop. Riepilogo delle prove: VirusTotal 3/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 69/100. Registrar: Cloudflare Pages.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
This domain operates as a cryptocurrency airdrop scam designed to deceive users into believing they can claim legitimate $TC tokens from TTcoin. The site presents itself as an official distribution platform, likely prompting visitors to connect wallets or submit sensitive credentials under false pretenses. Such scams typically harvest private keys, seed phrases, or personal information, enabling attackers to drain funds from victims' crypto wallets or commit identity fraud. Analysis indicates the domain was registered through Cloudflare Pages on May 20, 2026, and remains active as of investigation. Infrastructure review shows it resolves to 172.66.47.152, hosted in Canada under Cloudflare, Inc. VirusTotal reports zero detections across 95 security engines, suggesting the site has not yet been widely flagged. However, it appears on one security blocklist maintained by PhishDestroy. The SSL certificate, issued by Google Trust Services (WE1), provides transport encryption but does not validate legitimacy. Users who visited ttcoi.pages.dev should immediately disconnect any connected wallets and cease all interaction with the site. If credentials or wallet information were entered, revoke any connected dApp authorizations and transfer assets to a new, secure wallet. Monitor accounts for unauthorized transactions and enable multi-factor authentication where possible. Report the domain to relevant security platforms to aid in broader detection efforts. Given the low current detection rate, heightened vigilance is advised when encountering similar airdrop promotions.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.