MALICIOUS — CRITICAL
bonus-page.pages.dev Safety Check — Fake Airdrop Phishing
bonus-page[.]
The domain bonus-page.pages.dev was registered on March 24, 2026 and is presently serving a page titled "tether bet | promotions".
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bonus-page.pages.dev — Bilinen son aktif (HTTP 200). Dolandırıcılık türü: Fake Airdrop. Kanıt özeti: VirusTotal 3/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Sophos); PhishDestroy score 74/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
The domain bonus-page.pages.dev was registered on March 24, 2026 and is presently serving a page titled "tether bet | promotions". The content and title align with reports of a fake airdrop scheme that attempts to harvest credentials by masquerading as a legitimate promotional offer. The classification as a fake‑airdrop phishing site is derived from the known intelligence linking the domain to that specific scam type.
Infrastructure analysis shows the domain is hosted on a CDN provider’s network, resolving to IP address 188.114.96.3, which is associated with a large content‑delivery organization located in Canada. The domain employs HSTS and HTTP/3, and presents a TLS certificate issued by a publicly trusted certificate authority (WE1). Nameserver records point to collins.ns and marek.ns under the same CDN provider, confirming the use of that provider’s DNS services. Registration was performed through the CDN’s registrar service, indicating a rapid provisioning workflow.
Threat indicators include a listing on a single security blocklist and active blocking by a phishing‑specific blacklist. The site’s Gridinsoft trust score is 0 out of 100, reinforcing the malicious assessment. Although VirusTotal currently reports no detections, the lack of detections does not mitigate the observed phishing behavior. The page title and promotional phrasing are consistent with the fake airdrop narrative, providing concrete evidence of the intended deception.
Uncertainty remains around the ultimate payload or credential‑harvesting mechanisms, as no additional samples have been observed. Defenders should add the domain to outbound and inbound filters, monitor DNS queries for the associated nameservers, and consider sinkholing the IP range if feasible. Continued surveillance is advised to detect any evolution of the campaign, such as the deployment of new landing pages or the use of additional infrastructure components.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 4 identified
Customer support ticketing platform.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of bonus-page.pages.dev · checked Mar 25, 2026
Site Yapılandırma Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.