thesofaairdrop.pages.dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of thesofaairdrop.pages.dev
The domain thesofaairdrop.pages.dev appears to host a web page themed around cryptocurrency and cross-chain asset transfers. Based on the page title, metadata, and screenshot, it presents itself as a "Multichain" interface offering actions such as wallet connection, token claiming, staking, bridging, and swapping. The page also references several crypto-related services and communities, which suggests it is designed to attract users interested in Web3 tools, token rewards, or airdrop-style promotions.
The site is served from a pages.dev subdomain, which indicates it is likely deployed through a static hosting platform rather than operating as a standalone branded domain. The wording "airdrop" in the subdomain, combined with the visible "Claim" and "Claim Reward" buttons, may indicate an attempt to promote a token distribution or wallet-interaction flow. Based on the available content, it does not appear to be an official corporate website for a mainstream financial institution; rather, it appears to be a crypto-themed landing page that may be imitating an established decentralized-finance brand.
Safety Assessment for thesofaairdrop.pages.dev
Multiple independent signals raise concern about this domain at the time of this scan. It was flagged by 15 out of 91 security engines, with many of those detections classifying it as phishing or fraud-related. In addition, several web-classification providers categorized the site as phishing or financial fraud, while the screenshot shows branding associated with "Multichain" even though the actual host is thesofaairdrop.pages.dev. That mismatch between the displayed brand and the hosting domain may indicate a look-alike page intended to collect wallet connections or other sensitive actions.
Blacklist and threat-database results were mixed rather than fully clean. Major content-malice databases in the provided scan did not detect threats at the time of this scan, but one blacklist source did list the domain, which adds to the caution. The malware scan itself did not flag hosted files, though it did note low-confidence suspicious references to external crypto-related domains; on its own that would be weak evidence, but here it is outweighed by the broader phishing consensus across security engines and the page's impersonation-style presentation.
Taken together, the combination of multi-engine phishing detections, fraud-oriented categorization, crypto wallet interaction prompts, and branding that appears inconsistent with the pages.dev host suggests elevated risk. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted behind Cloudflare infrastructure on IP address 172.66.44.144 and uses a valid TLS certificate issued by Google Trust Services, with expiry shown as 2026-09-15. The domain is a subdomain on pages.dev, which is commonly used for static-site deployment. WHOIS data provided for the parent registration indicates an age of about five years, and the nameservers are on Cloudflare.
From a security-configuration perspective, the certificate appears valid, but DNSSEC is unsigned in the provided data. A valid certificate only confirms encrypted transport to the host being visited and does not verify that the page content is trustworthy. In this case, the main technical concern is not transport security but the apparent use of a hosted subdomain to present crypto-branded wallet and reward actions that may not match the underlying domain identity.
Share your experience with this website. Was it safe? Did you encounter any issues?