lineabuildairdrop2[.]pages[.]dev
“Linea: The home network for the world”
Resumo das evidências
Analysis of the domain lineabuildairdrop2.pages.dev shows a high‑risk crypto‑drainer campaign that was taken offline before the report date of July 24, 2026. The domain was registered on February 21, 2026 through Cloudflare, Inc., and the authoritative hosting is provided by Cloudflare’s network (ASN 13335) with the resolved address 104.21.32.1 located in the United States. No TLS certificate is presented, indicating the site operated without HTTPS. Google Safe Browsing flagged the URL for social engineering, and the scam type is identified as a fake airdrop, consistent with the page title “Linea: The home network for the world”.
VirusTotal scans returned ten positive detections out of ninety‑three vendors, confirming malicious intent. The IP address appears on a single security blocklist and the domain is currently blocked by the PhishDestroy mitigation service. The limited infrastructure footprint—single IP, single registrar—suggests a low‑cost deployment typical of opportunistic crypto‑drainer operations. Uncertainty remains regarding the exact payload delivered to victims, as no sample or sandbox analysis is available, and the site’s content has not been archived.
Defenders should update URL filtering to include this exact domain, enforce TLS‑only policies to prevent connections to non‑TLS sites, and monitor Cloudflare‑hosted IP ranges for similar patterns. Incident response teams should also consider correlating outbound traffic to 104.21.32.1 with potential unauthorized wallet interactions and block related network flows. Continuous threat‑intel feeds should be consulted for any re‑use of the same infrastructure, and affected users should be instructed to revoke compromised cryptocurrency credentials and audit wallet activity.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo