heaven-airdrop[.]website
heaven-airdrop.website — İçerik kullanılamıyor. Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 3/93 (alphaMountain.ai, Fortinet, G-Data); 4 external blocklist matches; PhishDestroy score 82/100.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain heaven-airdrop.website was registered on February 21, 2026 and is currently taken offline. Infrastructure analysis shows it resolved to the IP address 188.114.96.3, which belongs to the Cloudflare network (AS13335) and is geolocated in the United States. The SSL certificate presented for the host is identified as WE1, indicating the use of a potentially self‑signed or low‑reputation certificate. Reputation services provide a consistent picture of malicious activity: Gridinsoft assigns a trust score of 0 out of 100, effectively marking the site as completely untrustworthy.
VirusTotal scans report that three of ninety‑three security vendors flagged the domain, confirming that at least a subset of commercial engines recognize it as suspicious. The domain appears on five independent blocklists—PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura—each of which classifies it under a crypto‑drainer scam type. No page title or additional content analysis is available, and the site’s HTTP response has not been captured because the service is offline. The combination of a recent registration date, Cloudflare‑hosted IP, low trust score, multiple blocklist listings, and partial vendor detections strongly suggests that the domain was used to lure cryptocurrency owners into transferring assets to attacker‑controlled wallets.
Defenders should continue to block the IP 188.114.96.3 at network perimeters, add heaven‑airdrop.website to DNS sink‑hole lists, and monitor outbound traffic for attempts to resolve or contact this domain. Given the Cloudflare front‑end, attackers may shift to alternative IPs within the same ASN; therefore, security teams should apply ASN‑wide filtering for AS13335 when suspicious crypto‑related traffic is observed. Ongoing threat‑intel feeds should be consulted for any re‑appearance of the domain or related indicators, and incident response playbooks should be updated to include this specific crypto‑drainer signature.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin