me-foundation[.]top
“Claim Your Share of the Arbitrum Ecosystem | Up to $25,000 for Active Wallets”
me-foundation.top — 内容不可用 (HTTP 502). 品牌冒充:Across; 诈骗类型:Fake Airdrop. 证据摘要: VirusTotal 2/93 (ChainPatrol, Seclookup); 1 external blocklist match (ScamSniffer); PhishDestroy score 58/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain me-foundation.top indicates a recent fake‑airdrop campaign targeting users of the Across brand. The domain was registered on 21 February 2026 and currently resolves to the IPv4 address 45.9.148.51, which is announced as part of AS49447 operated by Nice IT Services Group Inc. in the Netherlands. The web server presented an SSL certificate identified as “R11”, and a Gridinsoft trust score of 0 out of 100, reflecting a very low credibility rating. The page title retrieved from the site reads “Claim Your Share of the Arbitrum Ecosystem | Up to $25,000 for Active Wallets”, which aligns with the “Fake Airdrop” scam type listed in the intelligence.
The site impersonates the Across brand, although no direct visual evidence is available. The domain appears on two reputable blocklists—PhishDestroy and ScamSniffer—and two of ninety‑three VirusTotal scanners have flagged it as malicious. The overall risk rating is elevated, and the site is presently taken offline, leaving its operational status uncertain. Defenders should add me-foundation.top to internal URL filtering and host‑based deny lists, block outbound connections to the hosting IP 45.9.148.51, and monitor the underlying ASN for additional suspicious registrations.
Continuous observation of newly created domains that resolve to the same ASN or exhibit similar SSL characteristics is advisable, as threat actors often reuse infrastructure. Because the site is already listed on multiple blocklists, coordination with external threat‑intelligence feeds can accelerate remediation. Until the domain is definitively taken down, network‑level enforcement remains the most reliable mitigation.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。