aerodromefi[.]team
Evidence Summary
The domain aerodromefi.team is currently classified as a generic phishing site with an elevated risk rating and an active status as of August 04, 2026. Automated scans on VirusTotal show that 7 of 91 security vendors have flagged the domain, indicating malicious behavior despite the majority of scanners returning clean results. Independent blocklist aggregators have listed the domain on three separate security blocklists, and it is explicitly blocked by the PhishDestroy, MetaMask, and SEAL filtering services, reinforcing the consensus that the domain is used for phishing attempts.
No publicly available WHOIS, IP address, hosting provider, SSL certificate details, HTTP response codes, Safe Browsing verdicts, or Open Threat Exchange records have been disclosed in the current intelligence set, leaving the underlying infrastructure largely uncharacterized. The absence of these data points should be interpreted as a gap in visibility rather than evidence of benign activity.
Defenders are advised to enforce domain-level blocking for aerodromefi.team across perimeter and endpoint filters, incorporate the domain into internal threat‑intel feeds, and monitor for any new indicators such as resolved IP addresses or observed payloads. Continuous re‑evaluation of the domain on VirusTotal and blocklist updates is recommended to capture any changes in detection coverage.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-1785813255-aerodromefi.tea- PDF artifact
- PDF evidence
Report history 1
- Report 1 ⚠️ ESCALATION #1 (0h active): Phishing - aerodromefi[.]team
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
8 monitored external feeds No match
Detection timeline
-
First recorded
First stored value: Reachable
-
Domain status
Reachable → Unreachable
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
2 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of aerodromefi.team · checked Aug 4, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive