sui[.]airdropalert[.]us
“Google”
Zusammenfassung der Beweislage
Analysis of the domain sui.airdropalert.us, observed as offline as of the report date, indicates an active brand‑impersonation campaign targeting Google. The domain was registered through Dynadot LLC on 19 October 2025 and is served from the IP address 142.251.111.147, which belongs to AS15169 Google LLC and is geolocated in the United States. DNS resolution is handled by the Cloudflare name servers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com. No SSL certificate was presented at the time of observation, implying the site operated over plain HTTP.
The page title returned by the server reads “Google”, aligning with the declared brand target. The Gridinsoft trust score rates the domain at 0 / 100, and the domain appears on a single security blocklist (PhishDestroy). VirusTotal reports that 11 of 93 scanning engines flagged the domain, reinforcing the suspicion of malicious activity. The campaign is classified as a crypto scam, consistent with the “airdrop” terminology embedded in the subdomain.
Defenders should note the combination of a recent registration, use of reputable Cloudflare DNS, and hosting on a Google‑owned IP range, which can reduce initial suspicion. However, the lack of TLS, low trust score, and multiple vendor detections indicate a high likelihood of abuse. Recommended mitigation steps include adding sui.airdropalert.us to local deny lists, monitoring DNS queries for the associated Cloudflare name servers, and updating URL filtering rules to block the resolved IP address. Continuous re‑evaluation is advised, as the offline status may change if the operators reactivate the site.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 13.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Forensische Erkenntnisse
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt