chaingpt[.]airdrpsalerts[.]xyz
“Google”
chaingpt.airdrpsalerts.xyz — المحتوى غير متوفر. انتحال العلامة التجارية: Google; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 15/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); PhishDestroy score 95/100. مسجّل النطاق: Dynadot.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
On July 23, 2026, technical analysis was conducted on the domain chaingpt.airdrpsalerts.xyz, which is classified as a brand impersonation targeting Google. The domain was registered through Dynadot LLC on November 4, 2025 and is currently taken offline. DNS resolution points to the IP address 142.250.184.228, an address owned by Google LLC (AS15169) in the United States, a tactic often employed to lend perceived legitimacy to malicious sites. The domain is hosted on Cloudflare infrastructure, as indicated by the authoritative nameservers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com.
No TLS certificate was observed; the site does not serve HTTPS traffic, which further confirms the lack of a valid SSL deployment. The page title returned by the server is simply "Google," matching the declared brand target and reinforcing the impersonation intent. Security reputation services show that 15 of 95 VirusTotal scanners flagged the domain, and it is listed on one external security blocklist. The domain was also blocked by the PhishDestroy service, and Gridinsoft assigned a trust score of 0 out of 100, reflecting a high confidence of malicious behavior.
Although the site is offline and no page content was captured, the combination of a Google‑related page title, use of a Google‑owned IP address, and the presence on multiple threat intelligence feeds strongly indicates a deliberate attempt to deceive users by masquerading as a Google service. Uncertainty remains regarding the exact phishing kit or payload that may have been delivered while the site was active, as no additional artifacts such as login forms or scripts were observed. Defenders should continue to block the domain at the DNS and URL filtering layers, monitor for any re‑registration attempts, and consider adding the associated IP address to watchlists for anomalous traffic patterns that could indicate reuse in future campaigns.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: airdrpsalerts.xyz
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain airdrpsalerts.xyz behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب