getairdrops.net
“Ethereum Events”
getairdrops.net — Последний известный активный (HTTP 200). Олицетворение бренда: Ethereum; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET); URLQuery 7 alerts; Google Safe Browsing flagged; PhishDestroy score 100/100. Регистратор: Wild West Domains.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
This domain, getairdrops.net, is identified as a high-risk brand impersonation threat targeting Ethereum cryptocurrency users. Analysis indicates the site mimics legitimate Ethereum events and airdrop promotions to deceive victims into disclosing wallet credentials or transferring funds. The domain exhibits characteristics of a cryptocurrency drainer kit, designed to automatically siphon assets from compromised wallets upon interaction. No specific drainer kit variant has been conclusively attributed, but the behavioral patterns align with known cryptocurrency phishing frameworks. Infrastructure analysis reveals multiple technical indicators of compromise. The domain resolves to IP address 209.94.90.1, hosted on AS40680 (Protocol Labs) in the United States. It was registered on February 21, 2026, through Wild West Domains, LLC, an unusual creation date that may indicate domain spoofing or backdating. VirusTotal detection metrics report 18 out of 95 security vendors flagging the domain as malicious. Google Safe Browsing classifies the site as phishing, and it appears on one security blocklist. The SSL certificate is issued by Let's Encrypt (R12), a common choice for both legitimate and malicious sites due to its free and automated issuance process. As of the latest assessment, getairdrops.net has been taken offline, likely following abuse reports or automated takedown mechanisms. However, the domain remains registered, posing a residual risk of reactivation or migration to alternative infrastructure. Users who interacted with the site prior to its deactivation may still be vulnerable to follow-up attacks, including credential harvesting or malware deployment. It is recommended to monitor wallet activity for unauthorized transactions, revoke any connected dApp permissions, and verify the legitimacy of all cryptocurrency-related communications through official Ethereum channels.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | getairdrops.net |
malicious | Sinkholed |
| OpenDNS | getairdrops.net |
phishing | Phishing Block |
| Hagezi Threat Feed | getairdrops.net |
malicious | Sinkholed |
| DNS4EU | getairdrops.net |
malicious | Sinkholed |
| OpenDNS | bafybeihjxb2jf67pxhimee7t6ysyljalzvunipwsueqnlw3ld6cmuxy354.ipfs.inbrowser.link |
phishing | Phishing Block |
| DNS4EU | bafybeihjxb2jf67pxhimee7t6ysyljalzvunipwsueqnlw3ld6cmuxy354.ipfs.inbrowser.link |
malicious | Sinkholed |
| DigiCert UltraDNS | ipfs.io |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
Cloudflare Radar Scan Mar 2, 2026 · 22:47 UTCCloudflare Radar scan registered: View Radar report.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 9 identified
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of getairdrops.net · checked Mar 2, 2026
Сообщения сообщества
Сообщил 1 участник сообщества; впервые замечено 31.08.2025
- Сохранённые сообщения
- 1
- Уникальные URL
- 1
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание