securedappreward[.]xyz
securedappreward.xyz — Контент недоступний (HTTP 502). Тип шахрайства: Fake Airdrop. Зведення доказів: VirusTotal 3/95 (Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of securedappreward.xyz shows a credential‑phishing campaign that leverages a fake airdrop narrative. The domain was registered on February 21, 2026 and is currently taken offline, but historical data indicate it was actively used before removal. The site employed an SSL certificate identified as WE1, which does not provide any inherent trust beyond encryption. Network resolution points to the IP address 172.67.164.235, which belongs to AS13335 operated by Cloudflare, Inc., located in the United States.
This hosting choice is typical for short‑lived malicious infrastructure that benefits from the scalability and anonymity of a content‑delivery network. VirusTotal scans recorded three detections out of ninety‑five security vendors, confirming that at least a subset of scanners flagged the domain for malicious activity. Independent security blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura, have all listed the domain, and it appears on four broader blocklists, reinforcing the consensus that it is associated with phishing. The campaign’s classification as a "Fake Airdrop" indicates it likely promised cryptocurrency rewards to lure credentials, a common social‑engineering vector within the credential‑phishing threat category.
While the exact page content and HTTP response codes have not been disclosed, the available evidence is sufficient for defensive teams to take immediate action. Recommendations include adding securedappreward.xyz to deny‑list policies across DNS, proxy, and endpoint protection solutions, monitoring the associated Cloudflare IP for any resurgence of activity, and reviewing any internal logs for connections to the domain or its IP during the period leading up to its takedown. Continuous re‑evaluation of the IP address is advised, as Cloudflare‑hosted malicious actors may reuse the same address for new campaigns.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога