MALICIOUS — CRITICAL
Проверка домена pira.pages.dev на фишинг и безопасность
pira[.]
This domain, pira.pages.dev, is flagged for brand impersonation targeting cryptocurrency users through a fraudulent airdrop scheme.
- VirusTotal
- 4/91
- Blocklists
- 1 · ScamSniffer
- Доступность
- Последний известный активный · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
pira.pages.dev — Последний известный активный (HTTP 200). Тип мошенничества: Fake Airdrop. Сводка доказательств: VirusTotal 4/91 (ADMINUSLabs, BitDefender, G-Data, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 76/100. Регистратор: Cloudflare Pages.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
This domain, pira.pages.dev, is flagged for brand impersonation targeting cryptocurrency users through a fraudulent airdrop scheme. Analysis indicates the site mimics legitimate airdrop promotions to deceive victims into connecting wallets or disclosing private keys, likely deploying a crypto drainer script upon interaction. The page title explicitly displays 'Airdrop,' a common lure in such scams, and no legitimate brand association is identified, reinforcing its malicious intent.
Technical indicators confirm the domain's high-risk status. It resolves to IP 188.114.96.3, registered through Cloudflare Pages on May 17, 2026, with an SSL certificate issued by Google Trust Services (WE1). VirusTotal detection shows 3/95 security vendors flagging the domain as malicious. The infrastructure is hosted in Canada under Cloudflare, Inc., and the domain appears on two security blocklists. No entries are present in Google Safe Browsing at the time of analysis, but the low detection rate may reflect evasion tactics or recent deployment.
The domain remains active, with no takedown or sinkholing observed. Response actions should include immediate blocklisting at the DNS and network levels, as well as wallet address monitoring for associated drainer activity. Users are advised to verify airdrop legitimacy through official project channels only, avoid connecting wallets to unverified sites, and employ browser-based transaction simulators to detect malicious scripts. Given the persistent activity and low detection rate, heightened vigilance is warranted for similar impersonation schemes leveraging Cloudflare Pages infrastructure.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
“Malicious Website”
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.