6a1e57c25c550900080f2971--allora-claimdrop[.]netlify[.]app
“Allora Prime”
6a1e57c25c550900080f2971--allora-claimdrop.netlify.app — İçerik kullanılamıyor (HTTP 404). Dolandırıcılık türü: Crypto Drainer. Kanıt özeti: VirusTotal 3/91 (ChainPatrol, alphaMountain.ai, Forcepoint ThreatSeeker); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Kayıt kuruluşu: Netlify.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, identified as a crypto drainer, resolves to the public IPv4 address 35.157.26.135 and is hosted on the Netlify platform. The domain is active as of the assessment date, July 16 2026, and continues to resolve despite missing authoritative name server records (NS_NOT_FOUND). VirusTotal analysis shows three of ninety‑one security vendors have flagged the host, indicating a modest level of detection across scanning engines. The limited detection count, combined with the absence of a disclosed nameserver, suggests the infrastructure may be deliberately obfuscated to hinder attribution. No additional reconnaissance data such as page titles, content snapshots, or malware kits has been released, leaving the exact delivery mechanism and victim interaction unknown. Defenders should block DNS resolution to 35.157.26.135 and any sub‑domains of *.netlify.app that match the pattern "*allora-claimdrop*". Network intrusion detection signatures should be updated to flag HTTP traffic to this host, and endpoint monitoring tools should watch for known crypto‑drainer payloads that may be delivered from Netlify‑hosted URLs. Continuous re‑scanning of the domain on reputation services is advised to capture any changes in vendor detections.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org %100 güvenReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org %100 güvenNext.js is a React framework for developing single page Javascript applications.
nextjs.org %100 güvenNetlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com %100 güvenHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenVirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin