op[.]airdropsalert[.]us
“Google”
Zusammenfassung der Beweislage
The domain op.airdropsalert.us was registered through Dynadot LLC and first observed on October 18, 2025. Infrastructure analysis shows the domain resolves to IP address 142.250.188.4, which belongs to AS15169 Google LLC and is geographically located in the United States. The domain is served by Cloudflare nameservers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com, and it does not present an SSL certificate, leaving the connection unencrypted. The page title returned from the live host was "Google," and the threat profile lists the brand target as Google, confirming deliberate brand impersonation.
The malicious activity is classified as a crypto scam, and the site has been flagged by PhishDestroy and appears on one external security blocklist. Gridinsoft assigned a trust score of 0 out of 100, indicating a high likelihood of malicious intent. VirusTotal analysis shows that 13 of 93 scanning engines flagged the domain as malicious, reinforcing the suspicion. Current operational status is offline, suggesting that the hosting has been taken down or the domain has been disabled.
While the exact phishing vector (e.g., credential harvesting page or crypto wallet address) has not been publicly disclosed, the combination of brand impersonation, lack of TLS, low trust score, and multiple vendor detections provides strong evidence of a fraudulent campaign. Defenders should immediately block the domain at perimeter firewalls and DNS filtering solutions, add the IP 142.250.188.4 to blacklists, and monitor for any related sub‑domains or similar Cloudflare‑named resolvers. Continuous threat‑intel feeds should be consulted for any re‑registration attempts, and incident response teams should advise users to avoid any unsolicited communications referencing Google that direct to this domain.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Forensische Erkenntnisse
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt