MALICIOUS — CRITICAL
grasstokendrop.pages.dev için kimlik avı ve güvenlik kontrolü
grasstokendrop[.]
Analysis of the domain grasstokendrop.pages.dev indicates active phishing infrastructure targeting cryptocurrency users through a fraudulent airdrop scheme.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
grasstokendrop.pages.dev — Bilinen son aktif (HTTP 200). Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 3/91 (alphaMountain.ai, Fortinet, Google Safe Browsing); PhishDestroy score 76/100. Kayıt kuruluşu: Cloudflare Pages.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
Analysis of the domain grasstokendrop.pages.dev indicates active phishing infrastructure targeting cryptocurrency users through a fraudulent airdrop scheme. The domain, registered on November 5, 2024, via Cloudflare Pages, currently resolves to IP 188.114.96.3 (Cloudflare, Inc., Canada) and returns an HTTP 200 status. The page title explicitly claims affiliation with a 'Grass Token Airdrop Official Website' and promotes a token pre-sale with bonuses up to 200%, aligning with known airdrop scam tactics. SSL certification is provided by Google Trust Services (WE1), a common feature in both legitimate and malicious sites leveraging Cloudflare's infrastructure. Technical indicators include detection by three security vendors on VirusTotal and presence on one security blocklist (PhishDestroy). The domain employs standard web technologies (Bootstrap, Google Tag Manager, HTTP/3) and tracking tools (Statcounter), which are not inherently malicious but are frequently used in phishing campaigns to monitor victim interactions. Gridinsoft assigns a trust score of 0/100, reinforcing its classification as high-risk. While the exact content of the site remains unanalyzed, the combination of airdrop-themed branding, pre-sale incentives, and impersonation of a cryptocurrency token (Grass Token) suggests an intent to harvest credentials, private keys, or direct cryptocurrency transfers. Defenders should treat this domain as active phishing infrastructure and prioritize blocking at DNS, proxy, or endpoint levels. Further investigation may reveal associated wallet addresses or additional domains using similar naming conventions (e.g., 'grass token' variants). No evidence currently links this domain to a legitimate Grass Token project.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 7 identified
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com %100 güvenTwitter is a 'microblogging' system that allows you to send and receive short posts called tweets.
twitter.com %100 güvenAnalytics / tracking service — collects visitor behavior data for the site owner.
www.statcounter.com %100 güvenHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of grasstokendrop.pages.dev · checked Jun 10, 2026
Site Yapılandırma Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.