snapshot-hodl[.]fun
“HODL Airdrop”
snapshot-hodl.fun — 内容不可用 (HTTP 502). 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 2/93 (Ermes, Gridinsoft); PhishDestroy score 56/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain snapshot-hodl.fun was registered on February 21, 2026 and is presently taken offline. Technical analysis shows that it resolves to the IP address 172.67.144.45, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The site presented the page title “HODL Airdrop,” indicating a crypto‑focused airdrop scam, and the underlying infrastructure matches the known Airdrop Scam phishing kit.
The SSL certificate associated with the domain is identified as WE1, confirming the use of a standard TLS layer without additional validation. Reputation services flag the domain as highly risky: Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on a single security blocklist, specifically being blocked by PhishDestroy. VirusTotal analysis recorded detections from 2 of 93 scanned security vendors, reinforcing the malicious classification.
The elevated risk level is consistent with the observed indicators, and the combination of a low trust score, blocklist presence, and vendor detections suggests a deliberate attempt to lure cryptocurrency users into a fraudulent airdrop. Defenders should ensure that the IP address 172.67.144.45 and the associated ASN are added to network deny lists, enforce DNS filtering for the domain snapshot-hodl.fun, and monitor for any resurgence of the Airdrop Scam kit in related campaigns. Continuous telemetry from threat intelligence platforms should be consulted for new detections, and endpoint protection solutions should be tuned to flag the identified SSL fingerprint and the specific page title pattern to reduce exposure to similar crypto‑scam attempts.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。