airlanden[.]com
“Black Money Cleaning Machine Manufacturers, SSD Chemical”
Résumé des preuves
Analysis of the domain airlanden.com indicates a confirmed brand impersonation campaign targeting WhatsApp users, classified as elevated risk. The domain was registered on February 21, 2026, via an undisclosed registrar and currently resolves to the IP address 198.12.66.123, hosted on AS36352 (HostPapa) in the United States. Infrastructure analysis reveals the use of an SSL certificate issued under the R13 root, a detail often observed in low-reputation or short-lived phishing sites. The domain appears on a single security blocklist, specifically PhishDestroy, and is flagged by one of 93 security vendors on VirusTotal, suggesting limited but active detection.
Gridinsoft assigns a trust score of 0/100, while Scamadviser reports a score of 42/100, reflecting mixed but predominantly negative assessments from automated abuse-detection platforms. The page title, 'Black Money Cleaning Machine Manufacturers, SSD Chemical,' does not align with the declared brand target (WhatsApp) or typical phishing lures, indicating either a misconfiguration, a secondary fraudulent service hosted on the same domain, or an attempt to obscure the site's true purpose. No evidence of a phishing kit or specific lure type is available at this time. The domain was taken offline prior to this report, though historical infrastructure may remain accessible for forensic analysis.
Defenders are advised to monitor related IPs, particularly 198.12.66.123, for re-emergence of similar campaigns. Organizations should update blocklists to include this domain and its associated IP, and consider correlating this activity with other WhatsApp-branded fraud domains registered around the same period. Further investigation into the registrar and hosting provider may yield additional compromised or malicious domains linked to this threat actor.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Analyse forensique
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif