euler[.]airdropsalert[.]lol
“Google”
ملخص الأدلة
This domain euler.airdropsalert.lol is currently offline but historical data indicate it was used for a brand‑impersonation campaign targeting Google users with a fake airdrop lure. The domain was registered on 18 October 2025 through Dynadot LLC and resolved to the IPv6 address 2607:f8b0:4004:c23::69, which belongs to AS15169 owned by Google LLC and is located in the United States. The hosting infrastructure is fronted by Cloudflare, as evidenced by the authoritative name servers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com. No TLS certificate was observed, meaning the site was served over plaintext HTTP.
The page title returned was “Google”, matching the declared brand target. Threat intelligence shows the site was flagged by Google Safe Browsing for social‑engineering content, appears on one public blocklist, and was identified by PhishDestroy as malicious. VirusTotal recorded 13 positive detections out of 95 scanners, and the Gridinsoft trust score was 0 / 100, reinforcing the malicious assessment. Because the site is now taken offline, active exploitation cannot be confirmed, but the combination of brand impersonation, fake‑airdrop terminology, and multiple vendor detections demonstrates a high‑risk profile.
Defenders should ensure the domain is added to local deny lists, verify that any internal DNS resolvers block both the IPv6 address and its associated A‑record, and monitor for newly‑registered look‑alike domains under the airdropsalert.lol second‑level domain. Continuous ingestion of blocklist feeds that flagged this indicator, as well as periodic re‑query of Google Safe Browsing, will help detect re‑use of the same infrastructure. Given the absence of a TLS certificate, any future redeployment would likely continue to rely on HTTP, simplifying detection through outbound request monitoring. Until the infrastructure is definitively retired, the domain should be treated as hostile and excluded from any allow‑list policies.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
Registration: airdropsalert.lol
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain airdropsalert.lol behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب