MALICIOUS — CRITICAL
1drop[.]cyou
The domain 1drop.cyou has been confirmed as a brand impersonation scam targeting the Solana cryptocurrency ecosystem.
- VirusTotal
- 17/94
- Blocklists
- 2 · MetaMask, SEAL
- 가용성
- 콘텐츠를 사용할 수 없음 · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
1drop.cyou — 콘텐츠를 사용할 수 없음 (HTTP 502). 브랜드 사칭: Solana; 사기 유형: Fake Airdrop. 증거 요약: VirusTotal 17/94 (alphaMountain.ai, Certego, Gridinsoft, SOCRadar); URLQuery 6 alerts; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 95/100. 등록기관: Global Domain Group.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Evidence Analysis
1drop.cyou: Confirmed Solana Brand Impersonation Scam
1drop.cyou identified as a high-risk brand impersonation site targeting Solana users. Flagged by 17/95 VirusTotal vendors, this domain mimics crypto airdrop.
The domain 1drop.cyou has been confirmed as a brand impersonation scam targeting the Solana cryptocurrency ecosystem. Analysis indicates this site specifically mimics legitimate Solana airdrop campaigns, presenting itself as an official token distribution portal under the title 'Airdrop Live | Claim Solana Token Airdrops.' As of the latest verification, the domain has been taken offline, though prior infrastructure remains a documented threat vector. Infrastructure analysis reveals the domain was registered through Global Domain Group LLC on March 24, 2026, an unusually future-dated creation entry suggesting possible registrar manipulation or data obfuscation. The domain resolved to IP address 104.21.94.10, geolocated to Canada and operated under Cloudflare, Inc., a common tactic to obscure hosting origins. Security telemetry shows the domain was flagged by 17 of 95 vendors on VirusTotal, with detection counts rising across three independent blocklists. No valid SSL certificate was present, further degrading trust indicators. Defensive platforms including PhishDestroy, MetaMask, and SEAL had actively blocked this domain prior to takedown. Current status indicates the domain is offline, though residual risk persists due to the recurring nature of brand impersonation campaigns. Users and network defenders are advised to treat any future resolution of 1drop.cyou as malicious and implement proactive blocking at DNS and network perimeter levels. Cryptocurrency wallet providers should integrate this domain into real-time threat intelligence feeds to prevent transaction routing. End users are cautioned against interacting with unsolicited airdrop claims, particularly those soliciting wallet connections or token transfers. Continuous monitoring of newly registered domains under similar naming patterns (e.g., [digit][word].cyou) is recommended to detect emergent threats.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
데이터 적용 범위12 recorded checks
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | dallying-reveler.fontmaxplugin.cc |
malicious | Sinkholed |
| DNS4EU | dallying-reveler.fontmaxplugin.cc |
malicious | Sinkholed |
| DigiCert UltraDNS | dallying-reveler.fontmaxplugin.cc |
malicious | Sinkholed |
| Cloudflare DNS | dallying-reveler.fontmaxplugin.cc |
malicious | Sinkholed |
| Cloudflare DNS | 1drop.cyou |
malicious | Sinkholed |
| Hagezi Threat Feed | 1drop.cyou |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
SHORTDOT 영역 · 공개 증거
.cyou
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
사용 기술 · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of 1drop.cyou · checked Mar 24, 2026
증거 및 외부 보고서Independent lookups and source reports
PD-20260324-912FFD Recipient: abuse@globaldomaingroup.com Victim safety and official reportingImmediate actions and verified reporting channels
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.