nvrk-reward[.]pages[.]dev
“Netvrk Staking”
nvrk-reward.pages.dev — 未验证. 品牌冒充:Fake Staking; 诈骗类型:Fake Airdrop. 证据摘要: VirusTotal 2/91 (alphaMountain.ai, LevelBlue); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 75/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies the domain nvrk-reward.pages.dev as an active crypto drainer campaign. The page mimics a reward platform to deceive users into connecting cryptocurrency wallets and authorizing malicious token transfers. No specific drainer kit signatures (e.g., MetaSploit, Inferno Drainer) were observed at time of analysis, indicating the payload may be dynamically served or obfuscated to evade static detection.
Technical indicators for nvrk-reward.pages.dev include: VirusTotal detection score of 0/95 engines (unflagged as of UTC 2024-06-06), registered through Cloudflare, Inc., resolving to IP 188.114.97.3 via Cloudflare CDN, and secured using a Google Trust Services SSL certificate. The domain was created on 2024-05-14 via Cloudflare Registrar and has not been flagged by Google Safe Browsing (GSB) or listed on blocklists such as PhishTank or OpenPhish at the time of assessment. No reverse DNS or WHOIS privacy is in use.
This domain remains active and unblocked across major browsers and security platforms. Immediate action is required: users should block 188.114.97.3 and nvrk-reward.pages.dev at the network and endpoint levels. Organizations are advised to push IOCs to SIEMs and EDRs via IOC sharing platforms such as MISP. Remaining risk is high due to absence of vendor detections and reliance on user vigilance to avoid wallet connections. Monitor for new variants under the same seed c52184, particularly on related Cloudflare Pages instances.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。