vwa-vanguard[.]xyz
“$VWA Airdrop”
vwa-vanguard.xyz — Conteúdo indisponível (HTTP 502). Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 12/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); 1 external blocklist match (ScamSniffer); PhishDestroy score 86/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, vwa-vanguard.xyz, is identified as a fraudulent airdrop scam designed to deceive cryptocurrency users. The site impersonates a legitimate token distribution event for $VWA, luring victims with promises of free assets. Once engaged, users are typically directed to connect their wallets to malicious smart contracts, which can result in unauthorized transactions, asset drainage, or complete loss of funds. The threat leverages social engineering tactics, exploiting the popularity of airdrops in the crypto space to gain trust and bypass initial skepticism. Analysis indicates this domain was registered on February 21, 2026, and is hosted on infrastructure associated with Cloudflare (IP: 104.21.40.206, AS13335). The site has been flagged by 12 out of 95 security vendors on VirusTotal, confirming its malicious nature. Additionally, it appears on two security blocklists and is explicitly blocked by multiple threat intelligence platforms. The SSL certificate, issued under the identifier WE1, does not correspond to any legitimate certificate authority, further indicating its fraudulent purpose. The page title, $VWA Airdrop, directly mimics promotional language used in genuine token distributions, enhancing its deceptive appearance. If you visited vwa-vanguard.xyz or interacted with its content, immediate action is required to mitigate potential risks. First, disconnect any wallets or accounts linked to the site and revoke any suspicious smart contract approvals using a blockchain explorer or wallet management tool. Monitor your wallet for unauthorized transactions and consider transferring assets to a new, secure wallet if tampering is suspected. Report the domain to relevant cybersecurity platforms to aid in broader threat mitigation efforts. Users should also enable multi-factor authentication on all crypto-related accounts and verify the legitimacy of any future airdrop promotions through official project channels before engagement.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo