rewards-lava[.]pages[.]dev
“Lava Points | Magma”
证据摘要
The domain rewards-lava.pages.dev is currently flagged as an active credential theft operation targeting cryptocurrency users under the guise of Lava Points rewards. Analysis indicates this infrastructure is designed to harvest login credentials, private keys, or wallet recovery phrases through deceptive prompts mimicking legitimate crypto reward platforms. The domain remains operational as of the latest verification, posing a direct risk to users interacting with its content. Infrastructure analysis reveals the domain was registered on March 28, 2026, through Cloudflare Pages, a platform frequently leveraged for rapid deployment of phishing pages. It resolves to the IP address 172.66.44.83, a Cloudflare-hosted endpoint with no prior association with legitimate Lava Points or Magma-branded services. The SSL certificate, issued by Google Trust Services (WE1), provides no inherent trust validation, as phishing domains commonly utilize free or automated certificate authorities. Detection metrics show the domain is flagged by 3 of 95 security vendors on VirusTotal, while appearing on 2 independent security blocklists. The page title, 'Lava Points | Magma,' directly impersonates a cryptocurrency rewards program, a tactic consistent with credential theft campaigns targeting digital asset holders. Current status confirms the domain remains active, with no takedown or mitigation measures observed. Users are advised to treat any interaction with rewards-lava.pages.dev as malicious. Network-level blocking of the IP 172.66.44.83 and domain-based filtering are recommended for organizations. Individuals who may have entered credentials or sensitive information should immediately revoke access to associated crypto wallets, rotate passwords, and monitor for unauthorized transactions. Verification of crypto reward offers should be conducted exclusively through official channels, with scrutiny applied to domains lacking verifiable ownership or established reputation.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控