grass-airdrop[.]pages[.]dev
“Grass: Earn A Stake in the AI Revolution”
证据摘要
This domain, grass-airdrop.pages.dev, is flagged as a high-risk brand impersonation campaign targeting users of airdrop schemes, specifically mimicking the Grass project. The domain was registered on March 29, 2026, through Cloudflare, Inc., and resolves to IP 188.114.97.3, located in Canada and belonging to Cloudflare. It uses Cloudflare nameservers desi.ns.cloudflare.com and norman.ns.cloudflare.com, and its SSL certificate is issued by Google Trust Services. The page title is Grass: Earn A Stake in the AI Revolution, and the domain remains active as of July 12, 2026, with an HTTP 200 status code. Analysis of the domain infrastructure reveals use of technologies including jsDelivr, HSTS, crypto-js, cdnjs, and HTTP/3, which are common in phishing kits designed to appear legitimate. The domain appears on five security blocklists and is blocked by services including PhishDestroy, MetaMask, ScamSniffer, SEAL, and Enkrypt. VirusTotal reports that 5 out of 95 security vendors flag this domain as malicious, indicating moderate but not universal detection across the security community. Scamadviser assigns a trust score of 11/100, and Gridinsoft gives a score of 0/100, both confirming high risk. The domain impersonates a legitimate airdrop project to deceive users into connecting wallets or providing credentials, likely leading to asset theft. What remains uncertain is the full scope of the campaign, including whether the domain is part of a larger network of phishing sites or if it targets specific geographic regions. Defenders should immediately block access to grass-airdrop.pages.dev at network and endpoint levels, add it to blocklists, and monitor for similar domains using the same IP range or Cloudflare infrastructure. Users who have interacted with this site should be warned to revoke any wallet permissions and change credentials. The domain creation date in March 2026 and active status suggest sustained operation, requiring ongoing vigilance.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
监控中的外部数据源 6 个 无匹配
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控