scr[.]airdropalert[.]us
“Google”
scr.airdropalert.us — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Google; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 15/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); PhishDestroy score 95/100. مسجّل النطاق: Dynadot.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain scr.airdropalert.us was registered on October 19, 2025 through Dynadot LLC and is currently taken offline. DNS resolution points to the IP address 142.251.111.105, which belongs to AS15169 Google LLC and is geolocated in the United States. The domain uses Cloudflare nameservers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com, but no TLS certificate is presented, indicating that the site was served over plain HTTP when it was active. The page title returned by the server is "Google," matching the declared brand target of Google and confirming a brand‑impersonation motive. Threat intelligence categorises the activity as a crypto‑scam, though the exact payload or lure was not captured in the available data.
Multiple security controls have flagged the domain. It appears on one external blocklist and is listed by PhishDestroy as malicious. The Gridinsoft trust score is 0 out of 100, reflecting extreme risk. VirusTotal analysis shows that 15 of 93 scanning engines flagged the domain, reinforcing the suspicion of malicious intent. The combination of a brand‑matching page title, lack of encryption, and association with a known crypto‑scam pattern suggests that the domain was used to lure victims into fraudulent cryptocurrency transactions.
Defenders should continue to block scr.airdropalert.us at network perimeter and DNS filtering layers, monitor for any residual traffic to the associated IP address, and consider adding the IP to reputation lists. Given the Cloudflare name server configuration, future sub‑domains could be spun up under the same authority; continuous watch of the registrar and name server records is advised. Incident response teams should also review any internal logs for connections to the domain or its IP during the active window, and ensure that endpoint protection solutions are updated to reflect the VirusTotal detections. The offline status does not guarantee cessation of activity, so ongoing vigilance is recommended.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب