airdrop-radrlabs[.]com
“Nur einen Moment…”
Riepilogo delle prove
Analysis indicates airdrop-radrlabs.com is associated with brand impersonation targeting airdrop-themed users, designed to mislead users into fraudulent engagement. The page title observed was "Nur einen Moment…", suggesting a German-language interstitial/loading behavior often used to delay content rendering and increase perceived legitimacy. Such patterns are frequently observed in phishing funnels that rely on transient redirect chains and obfuscated front pages. The infrastructure appears aligned with opportunistic scam campaigns mimicking cryptocurrency or reward distribution portals.
Infrastructure analysis shows multiple risk indicators across hosting, registration, and detection layers. VirusTotal reports 17/95 security vendors flagging the domain as malicious or suspicious. The domain was created on November 30 2025 and registered through Metaregistrar BV. It appears on 2 independent security blocklists including phishing-focused feeds. No SSL certificate is present, indicating either non-HTTPS operation or incomplete deployment. The domain resolves to IP 172.67.130.41 hosted on AS13335 Cloudflare, Inc. in the US, which is commonly used as a reverse proxy layer that can obscure origin infrastructure. Despite Cloudflare fronting, the absence of TLS and detection overlap suggests deliberate misuse of protective hosting to mask abusive content delivery.
Users who visited the domain should assume potential credential exposure, session token interception risk, or tracking activity depending on interaction level. Immediate mitigation should include clearing browser cache and cookies, revoking any credentials entered on the site, and changing passwords if reuse occurred across services. Endpoint malware scans are recommended to detect any secondary payload delivery. Because the domain is currently offline, direct access is not possible; however, historical resolution data and cached redirects may still pose residual risk. Security teams should monitor for related domains sharing similar naming patterns, certificate reuse, or IP adjacency to 172.67.130.41, as follow-on infrastructure is commonly deployed in campaigns of this type. Continuous monitoring of blocklists and threat intelligence feeds is advised to detect reactivation or clone deployments.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
9 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Stato del dominio
Non raggiungibile → Raggiungibile
Segnalazioni della comunità
Segnalato da 1 membro della comunità; prima osservazione il 03/12/2025
- Segnalazioni memorizzate
- 1
- URL segnalati univoci
- 1
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo