sophon[.]airdrpsalert[.]life
“Google”
sophon.airdrpsalert.life — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Google; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 12/95 (ChainPatrol, BitDefender, CRDF, CyRadar, ESET); PhishDestroy score 86/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain sophon.airdrpsalert.life was observed hosting a brand‑impersonation campaign targeting Google. The site resolved to IP address 142.251.16.105, which belongs to AS15169, Google LLC, and is geolocated in the United States. No TLS certificate was presented, indicating that the service was delivered over plain HTTP. The page title returned by the server was "Google," matching the declared brand target.
Infrastructure analysis shows the domain was registered via Cloudflare, Inc., and the nameserver information could not be retrieved (NS_NOT_FOUND). The domain has been taken offline and is currently blocked by the PhishDestroy sinkhole, but it remains listed on at least one external security blocklist. VirusTotal scans recorded 12 detections out of 95 participating vendors, confirming that multiple commercial engines flagged the host as malicious. Independent reputation scoring from Gridinsoft assigned a trust score of 0 out of 100, reinforcing the malicious assessment.
The lack of an SSL certificate, combined with the low trust score and multiple vendor detections, suggests a deliberate attempt to lure victims to a non‑secure replica of a Google login portal. Defenders should continue to block the domain at DNS and proxy layers, monitor for any resurgence of the same IP address or Cloudflare‑associated registrant, and update internal threat intel feeds with the observed indicators. Because the site is offline, no further payload or credential‑harvesting behavior can be confirmed, and analysts should treat any future re‑activation as a high‑confidence indicator of renewed brand‑impersonation activity.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: airdrpsalert.life
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain airdrpsalert.life behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب