drop-chain[.]link
证据摘要
drop-chain.link was registered on February 21, 2026 and is presently taken offline. The domain resolves to the Cloudflare‑hosted address 104.21.67.140, which is advertised as belonging to AS13335 (Cloudflare, Inc.) and is geolocated in the United States. An SSL certificate identified as “WE1” is present, indicating that transport‑layer encryption is in use, but the certificate details do not reveal a legitimate organization. The page title returned by the web server is “Just a moment…”, and no further content has been captured for analysis.
Automated scanning on VirusTotal recorded five positive detections out of ninety‑three participating engines, confirming that several security products consider the domain malicious. Independent reputation services also flag the site: Gridinsoft assigns a trust score of 0 out of 100, and three public blocklists—PhishDestroy, ScamSniffer and Enkrypt—have listed the domain as hostile. The domain appears on three additional security blocklists, reinforcing the consensus that it is being used for malicious activity. The specific phishing campaign or impersonated brand has not been disclosed; the limited visible artifact is only the generic title, so the exact victim‑targeting vector remains uncertain.
Defenders should add drop-chain.link to URL filtering policies, block the associated IP range 104.21.67.140, and ensure that TLS inspection rules do not allow traffic to this host. Continuous monitoring of Cloudflare‑originated IPs linked to the domain is advised, as the infrastructure can be repurposed quickly. Organizations relying on threat‑intel feeds should ingest the blocklist entries from PhishDestroy, ScamSniffer and Enkrypt, and update internal detection signatures to capture the five VirusTotal‑reported indicators. Because the site is offline, active takedown is not possible, but maintaining defensive controls around the observed infrastructure reduces the risk of future re‑use.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控