securedappreward[.]xyz
securedappreward.xyz — 内容不可用 (HTTP 502). 诈骗类型:Fake Airdrop. 证据摘要: VirusTotal 3/95 (Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of securedappreward.xyz shows a credential‑phishing campaign that leverages a fake airdrop narrative. The domain was registered on February 21, 2026 and is currently taken offline, but historical data indicate it was actively used before removal. The site employed an SSL certificate identified as WE1, which does not provide any inherent trust beyond encryption. Network resolution points to the IP address 172.67.164.235, which belongs to AS13335 operated by Cloudflare, Inc., located in the United States.
This hosting choice is typical for short‑lived malicious infrastructure that benefits from the scalability and anonymity of a content‑delivery network. VirusTotal scans recorded three detections out of ninety‑five security vendors, confirming that at least a subset of scanners flagged the domain for malicious activity. Independent security blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura, have all listed the domain, and it appears on four broader blocklists, reinforcing the consensus that it is associated with phishing. The campaign’s classification as a "Fake Airdrop" indicates it likely promised cryptocurrency rewards to lure credentials, a common social‑engineering vector within the credential‑phishing threat category.
While the exact page content and HTTP response codes have not been disclosed, the available evidence is sufficient for defensive teams to take immediate action. Recommendations include adding securedappreward.xyz to deny‑list policies across DNS, proxy, and endpoint protection solutions, monitoring the associated Cloudflare IP for any resurgence of activity, and reviewing any internal logs for connections to the domain or its IP during the period leading up to its takedown. Continuous re‑evaluation of the IP address is advised, as Cloudflare‑hosted malicious actors may reuse the same address for new campaigns.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。