MALICIOUS — CRITICAL
airdrop-162[.]pages[.]dev
PhishDestroy has identified a phishing domain, airdrop-162.pages.dev, which is actively involved in brand impersonation targeting Coinbase.
- VirusTotal
- 2/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
airdrop-162.pages.dev — Bilinen son aktif (HTTP 200). Marka kimliğine bürünme: Coinbase; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 2/91 (alphaMountain.ai, Forcepoint ThreatSeeker); PhishDestroy score 71/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
PhishDestroy has identified a phishing domain, airdrop-162.pages.dev, which is actively involved in brand impersonation targeting Coinbase. This domain, registered on May 15, 2025, employs a deceptive page title—'空投项目雷达 - 发现最新加密货币空投机会 | 2025年最全空投追踪平台'—to lure cryptocurrency enthusiasts into a fake airdrop scheme. The threat type is brand impersonation, and while no specific drainer kit has been confirmed, the domain's design and purpose strongly suggest it aims to harvest credentials or trick users into connecting wallets, leading to asset theft.
Technical indicators paint a clear picture of the threat. VirusTotal shows 0 out of 95 security vendors detecting the domain as malicious, indicating it has not yet been widely flagged. The domain is registered through Cloudflare, Inc., and resolves to IP address 172.66.47.164. Its SSL certificate is issued by Google Trust Services (WE1), lending an air of legitimacy. Additionally, the domain appears on one security blocklist, and its creation date is recent, suggesting it is part of an ongoing campaign. Google Safe Browsing status was not provided, but the combination of these factors underscores the risk.
Currently, the domain remains active and under investigation by PhishDestroy. The risk level is classified as under_investigation, meaning analysts are gathering further evidence. Users who encounter airdrop-162.pages.dev should avoid interacting with it entirely. PhishDestroy recommends verifying any cryptocurrency airdrop offers through official Coinbase channels and never connecting wallets or entering credentials on third-party sites. Immediate reporting of this domain to security teams and blocklists is advised to prevent further victimization.
Veri kapsamı13 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.