wlfi[.]portal-drops[.]icu
“Google”
wlfi.portal-drops.icu — Contenido no disponible (HTTP 502). Suplantación de marca: Google; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 6/95 (ChainPatrol, alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker); PhishDestroy score 68/100. Registrador: Dynadot.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This site, wlfi.portal-drops.icu, presented a page titled "Google" and was identified as impersonating the Gmail brand. The threat posed is impersonation, likely attempting to deceive users into believing they are accessing a legitimate Google or Gmail service to capture credentials or sensitive information.
Technical analysis shows the domain was flagged by 6 out of 95 VirusTotal vendors, with detection by ChainPatrol, alphaMountain.ai, CRDF, CyRadar, and Forcepoint ThreatSeeker. It was registered through Dynadot LLC, created on 2025-10-20, and resolves to IP 142.250.31.105, hosted by AS15169 Google LLC in the United States. The site lacks SSL encryption and uses nameservers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com.
The domain is currently DOWN/OFFLINE. GridinSoft trust is rated 0/100, and the DOM risk score is 10, indicating a high-risk, malicious site.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ZONA SHORTDOT · PRUEBAS PÚBLICAS
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Registration: portal-drops.icu
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain portal-drops.icu behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.