airdrop[.]dagama[.]network
“Nur einen Moment…”
Сводка доказательств
The domain airdrop.dagama.network was registered on 21 February 2026. DNS resolution points to the IPv4 address 188.114.97.3, which is announced by AS13335, a Cloudflare network endpoint located in the United States. The site is currently listed as offline, but historical observations indicate that it served a page whose title was “Nur einen Moment…”. The page title, together with the classification of the campaign as a “crypto drainer”, suggests that the site was intended to lure victims into transferring cryptocurrency to an attacker‑controlled wallet.
The infrastructure details align with a typical crypto‑scam pattern that leverages Cloudflare’s CDN to mask the true backend location. Reputation data shows that the domain appears on a single security blocklist, specifically PhishDestroy, and has been flagged by one of ninety‑three VirusTotal scanners. The SSL certificate presented to clients is identified as “WE1”, a generic certificate that provides no additional trust signals. No further public intelligence, such as Safe Browsing or Open Threat Exchange entries, is available for this domain at the time of analysis.
Uncertainty remains regarding the exact phishing kit, the specific cryptocurrency addresses used, and whether any victims reported financial loss before the takedown. Defenders are advised to continue blocking the domain at perimeter filters, update DNS blacklists with the observed IP address 188.114.97.3, and monitor for any resurgence of similarly named subdomains that share the same registrar or hosting profile. Incident response teams should also correlate internal logs for any connections to the listed IP or TLS handshake with the WE1 certificate, as these artifacts may indicate attempts to contact the now‑inactive infrastructure.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
10 внешних источников под наблюдением Совпадений нет
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание