cetus[.]airdropalert[.]us
“Google”
Resumen de las pruebas
This domain, cetus.airdropalert.us, was identified as a high-risk brand impersonation site targeting Google, specifically designed to facilitate a cryptocurrency scam. Registered on October 19, 2025, through Dynadot LLC, the domain has since been taken offline, though infrastructure analysis reveals key indicators of malicious activity. The page title explicitly displayed 'Google,' aligning with the known scam type of crypto fraud. No SSL certificate was present, increasing the likelihood of unencrypted data transmission and further exposing potential victims to interception risks. Infrastructure analysis shows the domain resolved to the IP address 142.250.176.196, which is associated with AS15169 (Google LLC) in the United States.
While the IP itself is linked to a legitimate provider, the domain's use of Cloudflare nameservers (brenna.ns.cloudflare.com and hassan.ns.cloudflare.com) suggests an attempt to obscure its origin and evade basic detection mechanisms. Google Safe Browsing flagged the domain for social engineering, a classification consistent with phishing or scam operations. Additionally, the domain appears on at least one security blocklist, and 11 of 93 security vendors on VirusTotal detected it as malicious, though the absence of further context limits the granularity of these detections. Defenders should treat this domain as a confirmed threat, particularly given its association with cryptocurrency fraud.
The lack of SSL, combined with the use of Cloudflare infrastructure and a registration through a low-friction registrar, aligns with common tactics used in scam campaigns. While the domain is currently offline, organizations should monitor for re-registration or similar domains under the airdropalert.us parent structure. Network-level blocking of the resolved IP during its active period is recommended, along with retrospective analysis of logs for connections to cetus.airdropalert.us or related subdomains.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 12/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Inteligencia forense
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.