saworld-airdrop[.]pages[.]dev
“Home | SA Campaign”
Kanıt özeti
PhishDestroy identifies saworld-airdrop.pages.dev as an active brand impersonation threat targeting cryptocurrency users via a fake airdrop scam. This domain leverages Cloudflare Pages for hosting and employs deceptive branding to trick victims into connecting wallets or entering sensitive data. The threat actor behind this infrastructure uses a drainer kit designed to silently siphon cryptocurrency from unsuspecting users’ wallets upon interaction.
This domain was flagged on Cloudflare Pages with a VirusTotal detection score of 0/95 as of the latest scan, indicating no antivirus or security vendor has yet flagged its payload. It resolves to IP address 188.114.96.3 and is registered under Cloudflare, Inc., which obscures the true owner behind proxy registration. The SSL certificate issued by Google Trust Services adds a veneer of legitimacy, while the lack of placement on Google Safe Browsing (GSB) or blocklists suggests its recent emergence and ongoing monitoring gap. No historical data on creation date is publicly accessible due to Cloudflare’s privacy protections.
The domain remains active and under investigation by threat intelligence teams. PhishDestroy recommends immediate blacklisting and user caution, as the absence of detections does not equate to safety. Users encountering this domain should not interact with it—avoid clicking, connecting wallets, or entering data. If exposure occurs, disconnect wallets, revoke any permissions, and scan systems with updated security tools. The risk remains high despite low detection scores, warranting enhanced monitoring and proactive blocking by security platforms.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Adli İstihbarat
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of saworld-airdrop.pages.dev · checked Apr 15, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin