rail[.]airdrpsalerts[.]life
“Welcome to nginx!”
rail.airdrpsalerts.life — No verificado. Tipo de estafa: Fake Airdrop. Resumen de las pruebas: VirusTotal 15/91 (ADMINUSLabs, ChainPatrol, BitDefender, Chong Lua Dao, ESET); PhishDestroy score 95/100. Registrador: Dynadot.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, rail.airdrpsalerts.life, presents a fraudulent AirDrop notification interface designed to deceive users into disclosing sensitive credentials or installing malicious payloads. The infrastructure mimics legitimate cryptocurrency or file-sharing alerts, a tactic commonly employed to exploit trust in peer-to-peer transfer services. Analysis of the page elements reveals no legitimate AirDrop functionality, with the displayed content serving solely as a lure to capture user interactions such as clicks or form submissions. The domain exhibits characteristics consistent with credential harvesting or malware distribution campaigns targeting mobile and desktop users alike.
Infrastructure analysis provides concrete indicators of malicious intent. The domain was registered on May 31, 2026, through Dynadot Inc, a registrar frequently leveraged for short-lived phishing operations. VirusTotal detection metrics show 7 out of 95 security vendors flagging the domain as malicious, while it appears on one additional security blocklist. The site resolves to IP address 104.21.76.250 and presents an SSL certificate issued by Google Trust Services (WE1), a common pattern observed in phishing domains attempting to appear legitimate. The page title, 'Welcome to nginx!', suggests either misconfigured server defaults or deliberate obfuscation of the true purpose.
Users who have visited rail.airdrpsalerts.life should immediately cease all interaction with the domain and perform a security review of their devices. If credentials were entered, reset passwords for all associated accounts using a separate, trusted device, and enable multi-factor authentication where available. Scan systems with updated endpoint protection tools to detect potential malware infections. Monitor financial and cryptocurrency accounts for unauthorized transactions, as phishing domains of this nature often serve as initial access vectors for broader compromise. Report the domain to relevant security teams or abuse contacts to assist in takedown efforts.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: airdrpsalerts.life
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain airdrpsalerts.life behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.