arb[.]airsdropsalert[.]cfd
“Google”
Gespeicherte Beobachtung
Beobachteter Titelkontrast
Zusammenfassung der Beweislage
This domain, arb.airsdropsalert.cfd, is flagged as a brand impersonation threat targeting Gmail users. Analysis indicates the infrastructure was designed to mimic Google’s login interface, as evidenced by the page title 'Google' and the use of an SSL certificate issued by Google Trust Services (WE1). No direct evidence of a crypto drainer kit was observed, but the domain’s design aligns with credential theft campaigns aimed at harvesting user account details. The threat actor likely sought to exploit trust in the Gmail brand to deceive victims into entering sensitive information. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 142.250.81.228, which is geolocated in the United States under AS15169 (Google LLC). The domain was registered on November 05, 2025, through Dynadot LLC, a registrar frequently observed in malicious campaigns. VirusTotal reports 13 out of 95 security vendors flagging the domain as malicious, while it appears on one security blocklist. The SSL certificate, though issued by a legitimate provider, does not mitigate the domain’s fraudulent intent. No Google Safe Browsing (GSB) detection was noted at the time of analysis, suggesting the domain may have evaded initial detection mechanisms. The domain is currently offline, having been taken down following detection. However, residual risk remains due to the potential for infrastructure reuse or re-registration under a similar name. Users who may have interacted with the domain are advised to reset their Gmail credentials immediately and enable multi-factor authentication. Organizations should monitor for related indicators of compromise, including the IP address and SSL certificate thumbprint, to prevent further exploitation. The elevated risk level is justified by the domain’s targeted impersonation of a high-value brand and its prior operational status.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
VirusTotal
13 → 14
Community-Meldungen
Von 1 Community-Mitglied gemeldet; erstmals gesehen am 13.11.2025
- Gespeicherte Meldungen
- 1
- Eindeutige gemeldete URLs
- 1
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
SHORTDOT-ZONE · ÖFFENTLICHE BELEGE
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Registration: airsdropsalert.cfd
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For the registrable domain airsdropsalert.cfd behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of arb.airsdropsalert.cfd · checked Mar 2, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt