cetus[.]airdrpsalerts[.]life
“Google”
cetus.airdrpsalerts.life — No verificado. Suplantación de marca: Google; Tipo de estafa: Generic Phishing. Resumen de las pruebas: VirusTotal 9/95 (ADMINUSLabs, ChainPatrol, CyRadar, ESET, Lionic); PhishDestroy score 78/100. Registrador: Cloudflare.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, cetus.airdrpsalerts.life, has been identified as a brand impersonation threat specifically targeting Google. The domain is currently offline, but prior activity indicates an attempt to mimic legitimate Google services for malicious purposes. Analysis confirms the domain was designed to deceive users by replicating Google’s branding, including an identical page title of 'Google' and an SSL certificate issued by Google Trust Services under the WE1 intermediate authority. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc., and resolves to the IP address 142.250.65.228, which is geolocated to the United States under AS15169 (Google LLC). Despite the IP association with a legitimate provider, the domain itself has been flagged by 9 of 95 security vendors on VirusTotal, indicating a high likelihood of malicious intent. Additionally, the domain appears on one security blocklist and was actively blocked by at least one threat intelligence feed prior to being taken offline. The SSL certificate, while issued by a trusted provider, does not mitigate the risk posed by the domain’s impersonation tactics. The current status of cetus.airdrpsalerts.life is offline, reducing immediate exposure risk. However, organizations and users are advised to treat this domain as a confirmed threat. Network administrators should ensure the domain is added to blocklists at the DNS and proxy levels to prevent accidental access. Endpoint protection systems should be updated to recognize the domain’s indicators of compromise, including its resolved IP and SSL certificate details. Users who may have interacted with the domain should verify their accounts for unauthorized activity, particularly if credentials were entered. Monitoring for similar domains registered through the same registrar or resolving to the same IP range is recommended to preempt further impersonation attempts.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: airdrpsalerts.life
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain airdrpsalerts.life behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 4 identified
Popular CSS framework for responsive, mobile-first web development.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.