destra-reward[.]com
destra-reward.com — Непроверенный. Тип мошенничества: Fake Airdrop. Сводка доказательств: VirusTotal 3/95 (Fortinet, Gridinsoft, Seclookup); PhishDestroy score 65/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain destra-reward.com indicates it was registered on September 13, 2025, through NiceNIC International Group Co., Limited, and is classified as a fake airdrop phishing operation. As of July 24, 2026, the domain is offline, though prior infrastructure reveals it was hosted behind Cloudflare (AS13335) with nameservers brynne.ns.cloudflare.com and carlos.ns.cloudflare.com. The domain resolved to IPv6 address 2606:4700:3033::6815:418, a Cloudflare network segment commonly used to mask origin servers. No SSL certificate was detected, increasing the likelihood of unencrypted credential harvesting. The page title 'Just a moment...' aligns with Cloudflare interstitial pages, suggesting the domain was either in staging or actively filtering traffic before serving phishing content.
Detection data is limited but consistent with phishing activity: three security vendors on VirusTotal flagged the domain, and it appears on at least one blocklist, though the specific blocklist name is not provided. Trust scores from Scamadviser (10/100) and Gridinsoft (0/100) further indicate high risk, though these metrics are derived from automated heuristics rather than manual analysis. The domain was blocked by PhishDestroy, a commercial phishing protection service, reinforcing its classification as malicious. The exact brand or project being impersonated remains unclear, as no specific entity is named in available data.
The scam type is identified as a fake airdrop, a tactic commonly used to deceive users into connecting wallets or submitting credentials under the guise of token distributions. Defenders should treat this domain as compromised infrastructure and consider it part of a broader phishing campaign targeting cryptocurrency users. Network-level blocking of the domain and associated IP ranges is recommended, along with monitoring for related domains registered through the same registrar or hosted on Cloudflare with similar naming patterns.
Сигналы безопасности
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 03:01:54 UTC
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание