cherrybot-airdrop[.]website
“Cherry AI - The Alpha Engine of Web3”
Kanıt özeti
The domain cherrybot-airdrop.website was registered on 21 February 2026 and taken offline prior to the report date of 24 July 2026. DNS resolution points to the IP address 172.67.197.91, which belongs to AS13335 Cloudflare, Inc. and is located in the United States. The site presented the page title “Cherry AI – The Alpha Engine of Web3”, indicating a focus on blockchain‑related services, and the SSL certificate is identified as WE1. Threat intelligence classifies the activity as a crypto drainer, a subset of crypto scams that aim to exfiltrate digital assets from victims.
The domain is listed on five independent blocklists—PhishDestroy, ScamSniffer, Polkadot, Enkrypt and Codeesura—demonstrating that multiple monitoring services have observed malicious behavior. VirusTotal analysis shows that two of ninety‑three scanning engines returned a positive detection, confirming that at least a minority of security products recognize the site as malicious. No additional public indicators such as sandboxed payloads or command‑and‑control endpoints have been disclosed.
The combination of a recent registration, Cloudflare hosting, a targeted page title, blocklist inclusion, and partial vendor detection suggests a purpose‑built infrastructure for credential or wallet harvesting. Defenders should add cherrybot‑airdrop.website to URL filtering rules, enforce outbound traffic restrictions to the associated IP address, and monitor for related Cloudflare‑hosted sub‑domains that may be leveraged in future campaigns. Continuous re‑evaluation is advised, as the underlying IP is shared by many legitimate services and could be repurposed for other malicious actors.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | 1.1.1.1 |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
6 izlenen harici kaynak Eşleşme yok
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin