defillama-airdrop[.]blogspot[.]com
“DeFiLlama Airdrop — Full 2025 Guide”
defillama-airdrop.blogspot.com — Контент недоступний. Уособлення бренду: Across; Тип шахрайства: Airdrop Scam. Зведення доказів: VirusTotal 2/95 (ChainPatrol, alphaMountain.ai); PhishDestroy score 56/100. Реєстратор: GOOGLE (ASN: 15169).
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain defillama-airdrop.blogspot.com was a crypto drainer phishing site designed to steal cryptocurrency from victims by tricking them into connecting their wallets to a malicious smart contract. It operated as an airdrop scam, impersonating no legitimate brand but using the name 'DeFiLlama' to appear credible. The site is currently taken offline, but users who interacted with it remain at risk of unauthorized token transfers.
Technical analysis shows defillama-airdrop.blogspot.com was flagged by 2 of 95 VirusTotal security vendors, including ChainPatrol and alphaMountain.ai. It appeared on 1 security blocklist (PhishDestroy) but was not flagged by Google Safe Browsing. The domain was registered through GOOGLE (ASN: 15169) and resolved to the IP address 142.251.111.132, hosted by Google LLC in the US. The SSL certificate was issued by Google Trust Services / WE2. The observed page title was 'DeFiLlama Airdrop — Full 2025 Guide', and the site used technologies including Blogger, Java, Python, and OpenGSE. At the time of assessment, the domain returned an HTTP 404 status.
Victims of defillama-airdrop.blogspot.com should immediately revoke any token approvals granted to unknown or suspicious smart contracts using tools like Etherscan or Revoke.cash. Funds should be moved to a new, secure wallet to prevent further unauthorized access. If credentials or private keys were entered, users must assume compromise and monitor accounts for fraudulent activity. The domain can be reported to Google Safe Browsing, PhishTank, or the Anti-Phishing Working Group (APWG) to aid in takedown efforts.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 5 identified
Blogger is a blog-publishing service that allows multi-user blogs with time-stamped entries.
www.blogger.com 100% впевненостіJava is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com 100% впевненостіOpenGSE is a test suite used for testing servlet compliance. It is deployed by using WAR files that are deployed on the server engine.
code.google.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога