claim-ro[.]pages[.]dev
Перевірка домену claim-ro.pages.dev на фішинг і безпеку
“Ro | Airdrop”
claim-ro.pages.dev — Останній відомий активний (HTTP 200). Тип шахрайства: Fake Airdrop. Зведення доказів: VirusTotal 3/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 84/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as a high-risk brand impersonation threat targeting cryptocurrency users through a fraudulent airdrop scheme. Analysis indicates the site mimics legitimate reward distributions to deceive victims into disclosing wallet credentials or transferring funds under false pretenses. Infrastructure analysis reveals the domain claim-ro.pages.dev is hosted on Cloudflare infrastructure (AS13335) and resolves to IP address 172.66.44.105, located in the United States. The SSL certificate is issued by Google Trust Services (WE1), a common provider for both legitimate and malicious sites. Security telemetry shows 1 of 95 vendors on VirusTotal detect the domain as malicious, while it appears on 3 independent security blocklists. The page title 'Ro | Airdrop' directly references the fraudulent reward theme, and the domain remains actively serving content at the time of assessment. Mitigation requires immediate blocking of the domain and IP across network security controls. Users should verify airdrop legitimacy through official project channels only, never through unsolicited links. Wallet software should be configured to warn against interactions with newly registered domains (this one uses Cloudflare's registrar) or those lacking verifiable project associations. Cryptocurrency holders are advised to treat all airdrop claims requiring wallet connections as high-risk until confirmed through multiple trusted sources.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога