sommia[.]network
“Somnia Airdrop”
Сводка доказательств
The domain sommia.network was registered on 2026-02-21 and is currently taken offline. Analysis indicates that the site hosted a crypto‑airdrop phishing campaign, as reflected by the page title “Somnia Airdrop” and the classification of the kit as an “Airdrop Scam”. The infrastructure points to a single IPv6 address 2606:4700:3035::ac43:c786, which belongs to Cloudflare (AS13335) and resolves to a location in the United States. The SSL certificate presented under the label “WE1” was observed, confirming that HTTPS was in use while the site was active. Five of ninety‑three VirusTotal scanners flagged the domain as malicious, and it appears on five external blocklists.
It has been listed by PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. Gridinsoft assigned a trust score of 0 out of 100, indicating a high confidence of malicious intent. AlienVault OTX includes the domain in one threat‑intelligence pulse, further corroborating its association with crypto‑related scams. No additional content or payload details have been published, and the exact phishing landing page layout remains unverified because the site is offline. The limited number of vendor detections suggests that many scanners have not yet observed the payload, but the presence on multiple blocklists and the low trust score provide strong evidence of abuse.
Defenders should block resolution of 2606:4700:3035::ac43:c786 at the network perimeter and add sommia.network to URL filtering and email security policies. Continuous monitoring of Cloudflare‑hosted IPv6 ranges for similar airdrop‑related activity is advised. Incident response teams should treat any email or message referencing a “Somnia Airdrop” as suspicious and quarantine related artifacts. Finally, maintain updated threat‑intel feeds to capture any re‑use of the domain or its infrastructure in future campaigns.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 10.08.2026
6 внешних источников под наблюдением Совпадений нет
Криминалистическая аналитика
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание