fuel[.]airdrpsalert[.]locker
“Google”
The domain fuel.airdrpsalert.locker is a phishing site that engages in brand impersonation, specifically targeting Google. This domain poses an elevated risk to users and is currently taken offline. It has been flagged by 9 of 95 VirusTotal vendors, including ChainPatrol, alphaMountain.ai, and CRDF, and appears on 1 security blocklist, PhishDestroy. The domain was registered through Dynadot LLC on October 26, 2025, and resolves to the IP address 142.251.140.164, which is located in the US and belongs to AS15169 Google LLC. The site has no SSL certificate, and the page title observed was 'Google'.
fuel.airdrpsalert.locker has a Gridinsoft trust score of 0/100, indicating a high level of suspicion. The domain is registered through Dynadot LLC and was created on 2025-10-26 14:33:37. It resolves to the IP address 142.251.140.164, which is associated with Google LLC. Despite this, the domain has been flagged by 9 of 95 VirusTotal vendors and is listed on the PhishDestroy blocklist. The lack of an SSL certificate further raises concerns about the security and legitimacy of the site.
To protect against the risks posed by fuel.airdrpsalert.locker, users should change their Google passwords immediately and enable two-factor authentication if they have not already done so. They should also monitor their accounts for any unauthorized activity or fraud. If any suspicious transactions are detected, users should report them to Google and their financial institutions. Additionally, users can report the domain to PhishDestroy and other security organizations to help prevent further phishing attempts.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: airdrpsalert.locker
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain airdrpsalert.locker behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Forensic Intelligence
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive