euler[.]airdrpsalerts[.]click
“Google”
euler.airdrpsalerts.click — Belum terverifikasi. Peniruan identitas merek: Google; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 14/91 (ChainPatrol, BitDefender, Chong Lua Dao, CyRadar, ESET); PhishDestroy score 92/100. Registrar: Dynadot.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis of euler.airdrpsalerts.click indicates that the domain was actively used for a brand‑impersonation campaign targeting Google. The domain was registered through Dynadot LLC on 4 November 2025 and resolves to the IP address 172.253.62.105, which is assigned to AS15169 Google LLC in the United States. Although the IP belongs to Google’s network, the domain is not associated with any legitimate Google service; it presents no SSL certificate and therefore does not offer a secure HTTPS endpoint. The authoritative name servers are brenna.ns.cloudflare.com and hassan.ns.cloudflare.com, confirming the use of Cloudflare’s DNS infrastructure for the malicious site.
The HTTP response that was observed returned a page title of “Google”, directly matching the declared brand target and reinforcing the impersonation intent. VirusTotal records show detections from 16 of 95 security vendors, and the domain is listed on at least one public blocklist, with PhishDestroy explicitly blocking it. Gridinsoft assigns a trust score of 0 out of 100, reflecting a high confidence of malicious behavior. The site is currently offline, but the historical evidence suggests it was employed to lure victims into a credential‑stealing flow.
Uncertainty remains regarding the exact payload or login form that was served before takedown, as no visual or content analysis is available. Defenders should maintain blocks on the domain at DNS and network layers, monitor for any re‑registration of the same hostnames or reuse of the IP address, and incorporate the observed indicators—such as the Cloudflare name servers, the IP 172.253.62.105, and the lack of TLS—into threat‑intel feeds. Reviewing outbound traffic logs for connections to this IP may reveal compromised accounts or additional malicious activity related to the impersonation campaign.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Registration: airdrpsalerts.click
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain airdrpsalerts.click behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Intelijen Forensik
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive