s2-asi[.]com
“Google”
Résumé des preuves
Analysis of s2-asi.com indicates a newly registered domain (19 Nov 2025) that is currently offline but was previously identified as a brand‑impersonation site targeting Google. The domain was registered via Dynadot LLC and configured to use Cloudflare’s DNS service, with the authoritative nameservers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com. Network resolution points to IP 216.58.206.68, an address owned by Google LLC (AS15169) and geolocated in Germany, suggesting the attacker deliberately pointed the domain to a legitimate Google server or leveraged a misconfiguration to obscure hosting details. The TLS certificate presented on the host is issued by Google Trust Services under the “WE1” profile, a certificate normally reserved for Google‑owned services, further reinforcing the intent to masquerade as an authentic Google endpoint.
HTTP probing returned a 404 status code, and the only visible page metadata is a title of “Google”. The site was flagged by two of ninety‑five VirusTotal scanners and is listed on a single external blocklist, where PhishDestroy has already taken action to block it. No additional detection sources such as Safe Browsing or OTX are cited in the available intelligence, and the content of the page has not been captured, leaving the exact phishing vector uncertain.
Given the combination of brand‑specific page title, legitimate‑looking SSL certificate, and the use of Cloudflare’s infrastructure, defenders should treat s2-asi.com as a high‑confidence impersonation threat. Recommended mitigation steps include adding the domain to DNS and web‑filter blocklists, monitoring the associated IP address for any resurgence of activity, and reviewing inbound traffic for attempts to reach the domain before it went offline. Continuous observation of newly registered domains that resolve to known corporate IP ranges and employ brand‑matching TLS certificates is advised to detect similar campaigns early.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 10/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
État du domaine
Inaccessible → Accessible
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif