gov-aerodrome[.]org
“Aerodrome Finance”
gov-aerodrome.org — Contenu indisponible. Usurpation de l'identité de la marque : Genericcrypto. Résumé des preuves: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; Google Safe Browsing flagged; Spamhaus DBL_PHISH; PhishDestroy score 92/100. Bureau d’enregistrement: Dynadot.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain gov-aerodrome.org was observed hosting a site with the page title “Aerodrome Finance”. The domain was registered on 06 December 2025 through Dynadot LLC and is currently taken offline. DNS resolution points to IP 104.21.53.158, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The authoritative name servers are alexa.ns.cloudflare.com and randall.ns.cloudflare.com, both Cloudflare‑operated. No TLS certificate was presented, indicating the site was served over plain HTTP or that the certificate was missing at the time of analysis.
Reputation services rate the domain poorly: Gridinsoft assigns a trust score of 0 out of 100, and Google Safe Browsing flags the URL for social‑engineering content. VirusTotal reports that 14 of 95 scanned security vendors flagged the domain, demonstrating a moderate level of detection across independent scanners. The domain appears on a single external blocklist and has been explicitly blocked by the PhishDestroy service, reinforcing the assessment that it is being used for malicious purposes. The available evidence points to a generic phishing operation that likely attempts to harvest credentials or financial information under the guise of an “Aerodrome Finance” portal.
Because the site is already offline, immediate mitigation focuses on preventing future resolution and credential reuse. Defenders should add the domain and its associated IP address to internal block lists, monitor for any CNAME or DNS changes that point to alternative hosting, and enforce strict email filtering rules for messages that reference “Aerodrome Finance” or similar phrasing. Continuous re‑query of reputation feeds is advised, as the threat actor may register new domains using the same naming pattern. At present, the lack of a TLS certificate, the low trust score, and multiple independent detections constitute sufficient evidence to classify the domain as high‑risk and to treat any related traffic as malicious.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif