MALICIOUS — CRITICAL
dawninternet.pages.dev のフィッシング・安全性チェック
dawninternet[.]
The domain dawninternet.pages.dev was registered on May 11, 2026 and is currently active.
- VirusTotal
- 12/91
- Blocklists
- 3 · MetaMask, ScamSniffer
- 可用性
- 最後に確認されたアクティブな状態 · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
dawninternet.pages.dev — 最後に確認されたアクティブな状態 (HTTP 200). ブランドの偽装: Dawn; 詐欺タイプ: Fake Airdrop. 証拠の概要: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Fortinet); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 100/100. レジストラ: Cloudflare.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
Evidence Analysis
The domain dawninternet.pages.dev was registered on May 11, 2026 and is currently active. DNS resolution points exclusively to the IP address 172.66.47.45, which is owned by Cloudflare, Inc. and geolocated to the United States (CA). The domain uses the Cloudflare authoritative nameservers plato.ns.cloudflare.com and sue.ns.cloudflare.com, indicating that the attacker is leveraging Cloudflare's proxy and CDN services to hide the true origin of any hosted content. A TLS certificate issued by Google Trust Services (WE1) is presented for the host, and an HTTP GET request returns a 200 status code with the page title “DAWN Internet – Decentralized Wireless Broadband Network”. The content mimics the legitimate brand “DAWN” and explicitly advertises a fake airdrop, a known social‑engineering lure. The site is listed on four independent blocklists – PhishDestroy, MetaMask, ScamSniffer, and SEAL – and VirusTotal reports that two of ninety‑five security engines have flagged the domain. Infrastructure scoring reflects a severe lack of trust: Gridinsoft assigns a score of 0 out of 100, and the limited VirusTotal detections suggest that the malicious payload has not yet been widely observed in sandbox environments. The use of Cloudflare’s edge network makes direct attribution to a backend server difficult, and no additional IP addresses or hosting details have been disclosed beyond the single resolver address. Defenders should block DNS resolution to dawninternet.pages.dev at the recursive resolver level and add the host to URL filtering policies for web gateways. Continuous monitoring of Cloudflare edge IP ranges for anomalous traffic to this domain is advised, as is periodic re‑scanning on VirusTotal to capture any new detections. Until further evidence of payload delivery emerges, the primary risk remains credential harvesting through the fake airdrop narrative, making early containment essential.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
データの網羅性12 recorded checks
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
公開ブロックリスト登録状況
VirusTotalによる分析
証拠および外部報告書Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。