liquidscan-claim[.]vercel[.]app
“$LQSCAN Airdrop by LiquidScan”
liquidscan-claim.vercel.app — Conteúdo indisponível. Representação da marca: MetaMask; Tipo de golpe: Airdrop Scam. Resumo das evidências: VirusTotal 3/93 (G-Data, Gridinsoft, Trustwave); 4 external blocklist matches; PhishDestroy score 82/100. Registrador: Tucows.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
On July 24, 2026 the domain liquidscan-claim.vercel.app was observed hosting a page titled “$LQSCAN Airdrop by LiquidScan”. The site was registered on February 21, 2026 through Tucows Domains Inc. and resolves to the IP address 216.198.79.131, which belongs to Amazon.com, Inc. (AS16509) and is hosted on the Vercel platform. HTTPS is enforced via HSTS and the TLS certificate is issued by Google Trust Services under the WR1 authority, indicating a valid certificate chain. The HTTP response returned status code 451, confirming that the content was unavailable at the time of testing.
Analysis of the page title and the “Airdrop Scam” kit classification suggests the operator is attempting a fake cryptocurrency airdrop to lure victims into disclosing private keys or sending funds. Threat intelligence feeds have placed the domain on five security blocklists, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. VirusTotal scans show three of ninety‑three security vendors flagged the domain, providing additional corroboration of malicious intent. No public Safe Browsing or OTX entries were supplied, and the limited exposure window (offline status) prevents direct observation of payloads or credential‑harvesting forms.
Consequently, the precise techniques used to exfiltrate assets remain uncertain, as does the identity of any associated command‑and‑control infrastructure. Defenders should immediately block resolution of liquidscan-claim.vercel.app at network perimeters and add the IP 216.198.79.131 to deny‑list rules. Email security gateways should be tuned to detect references to “LQSCAN” or “LiquidScan” airdrop promises, and users should be warned that any unsolicited offers claiming free LQSCAN tokens are fraudulent. Continuous monitoring of the hosting provider Vercel for new domains employing the same kit is advised, and incident response teams should be prepared to investigate any related wallet address disclosures that may arise from this campaign.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Vercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo