zreal-claim[.]pages[.]dev
“Z李REAL SUPER COIN | Airdrop”
zreal-claim.pages.dev — Conteúdo indisponível. Representação da marca: Revolut; Tipo de golpe: Airdrop Scam. Resumo das evidências: VirusTotal 3/93 (ADMINUSLabs, Gridinsoft, Phishing Database); 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain zreal-claim.pages.dev was registered on February 21 2026 through Cloudflare, Inc. and resolves to the Cloudflare‑owned address 172.66.47.133 located in the United States (AS13335). No TLS certificate is presented, indicating that the site was served over plain HTTP before being taken offline. The page title reported by crawlers is “Z李REAL SUPER COIN | Airdrop”, which aligns with the observed phishing kit labeled “Airdrop Scam” and the declared scam type “Fake Airdrop”. VirusTotal has recorded detections from three of ninety‑three scanning engines, confirming that the domain is recognized as malicious by a minority of vendors.
It is also listed on four independent blocklists, including PhishDestroy, MetaMask, ScamSniffer, and SEAL, all of which have explicitly blocked the domain. The combination of a recent creation date, use of Cloudflare’s infrastructure without SSL, and the presence of an airdrop‑related phishing kit suggests an intent to lure cryptocurrency users into submitting private keys or seed phrases, typical of crypto‑drainer campaigns. Because the site is currently offline, live content cannot be verified, and the exact payload or credential‑harvesting mechanism remains unknown. Defenders should continue to deny traffic to the IP 172.66.47.133, enforce blocklist updates that include the four named providers, and monitor for any future re‑registration of the sub‑domain or similar variations.
Additional scrutiny of outbound DNS queries for the “pages.dev” namespace is advised, as attackers frequently reuse Cloudflare‑hosted sub‑domains for fast‑flux deployments. The lack of HTTPS further simplifies detection via network‑level inspection. Organizations that have exposed wallet credentials to this domain should assume compromise and rotate all associated keys immediately.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo