pyth[.]airdropalert[.]us
“Google”
ملخص الأدلة
Analysis of the domain pyth.airdropalert.us, first observed on 19 October 2025, indicates a malicious infrastructure designed to impersonate Google in a crypto‑scam campaign. The domain is registered through Dynadot LLC and resolves to the IP address 142.250.80.36, which is announced by AS15169 Google LLC and geolocated to the United States. Despite the legitimate‑looking IP prefix, the site lacks an SSL certificate, exposing any traffic to clear‑text interception. The page title returned by the HTTP response is “Google”, matching the declared brand target.
The domain appears on a single security blocklist and is listed as blocked by the PhishDestroy feed. VirusTotal reports that 11 of 93 scanning engines flag the domain as malicious, reinforcing the suspicion of abuse. Gridinsoft assigns a trust score of 0 / 100, the lowest possible rating, and the nameservers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com point to Cloudflare’s DNS service, a common choice for fast deployment of malicious sites. The site is currently offline, but the combination of brand impersonation, crypto‑scam classification, and the observed detection footprint suggests that the infrastructure may be re‑used for future campaigns.
Defenders should add the domain and its associated IP address to deny‑list rules, monitor the Cloudflare nameservers for any re‑registration, and ensure that any internal URL filtering or Safe Browsing solutions are updated to reflect the observed blocklist entry. Because the domain uses no TLS, network‑level inspection can be performed without decryption overhead. Continuous telemetry from the 11 vendor detections should be reviewed for any emerging indicators of compromise linked to the same IP range.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب