pi-airdrop[.]ct[.]ws
“Pi Network – Get your free pi reward”
pi-airdrop.ct.ws — Непроверенный. Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 4/91 (alphaMountain.ai, Chong Lua Dao, Gridinsoft, LevelBlue); Spamhaus DBL_PHISH; PhishDestroy score 71/100. Регистратор: Namecheap.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of pi‑airdrop.ct.ws indicates a high‑risk cryptocurrency drainer operation. The site presents the page title “Pi Network – Get your free pi reward,” which is commonly used in fraudulent campaigns targeting users of the Pi Network project. The domain is currently active and classified as a crypto‑drainer, confirming its intent to lure victims into transferring digital assets.
Infrastructure analysis reveals the site is hosted on a server located in the United Kingdom, identified by IP address 185.27.134.34 belonging to AS34119 Wildcard UK Limited. The domain resolves through the Byet.org name server cluster (ns1.byet.org, ns2.byet.org, ns3.byet.org, ns4.byet.org, ns5.byet.org). The web stack consists of WordPress powered by PHP and MySQL, front‑ended by Nginx/OpenResty and enriched with jQuery, jQuery Migrate, and Font Awesome libraries. SSL is provided by ZeroSSL ECC Domain Secure Site CA, indicating a publicly available free certificate.
Reputation signals show a zero‑point trust rating from Gridinsoft, and five out of ninety‑five VirusTotal scanners have flagged the domain as malicious. The site is listed on a single security blocklist and has been actively blocked by the PhishDestroy service. HTTP requests return a 200 status code, confirming the site is serving content without immediate disruption.
Defenders should prioritize immediate containment by adding pi‑airdrop.ct.ws to network blocklists and DNS filtering rules. Continuous monitoring of the associated IP address and its ASN is advised, as the hosting provider may be leveraged for additional malicious domains. Incident response teams should also audit any inbound traffic that references the “Pi Network” reward phrasing, and consider sinkholing the domain to disrupt the campaign’s infrastructure.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 8 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Icon font library.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of pi-airdrop.ct.ws · checked Mar 2, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание