mmt[.]airdropsalert[.]us
“Google”
mmt.airdropsalert.us — Contenuto non disponibile. Simulazione del marchio: Google; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 14/93 (ChainPatrol, alphaMountain.ai, BitDefender, Certego, CRDF); PhishDestroy score 92/100. Registrar: Dynadot.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis of the domain mmt.airdropsalert.us indicates it was actively impersonating Google as part of a cryptocurrency scam, as documented in threat intelligence records dated July 23, 2026. The domain, created on October 18, 2025, and registered through Dynadot LLC, resolved to the IP address 172.253.63.105, which is associated with AS15169 (Google LLC) in the United States. Despite the IP's legitimate ownership, the domain itself was flagged by 14 of 93 security vendors on VirusTotal and appeared on at least one security blocklist, specifically PhishDestroy. The domain used Cloudflare nameservers (brenna.ns.cloudflare.com and hassan.ns.cloudflare.com) and lacked an SSL certificate, which is atypical for legitimate services but common in low-effort phishing infrastructure.
The page title was explicitly set to 'Google,' aligning with the brand impersonation noted in the intelligence data. Gridinsoft assigned a trust score of 0/100, further supporting its classification as malicious. The domain was categorized as a crypto scam, though specific details about the scam mechanics (e.g., fake wallets, airdrop lures, or credential harvesting) are not available in the provided data. As of the report date, the domain was offline, though defenders should treat it as part of a broader pattern of Google-branded cryptocurrency fraud.
Defenders are advised to block the domain at the DNS or proxy level, monitor for related infrastructure (e.g., similar Cloudflare-hosted domains or Dynadot registrations), and correlate logs for connections to 172.253.63.105 during the domain's active period. While the IP is owned by Google, its use in this context does not indicate compromise of Google's infrastructure but rather potential abuse of shared hosting or misconfigured services. No additional HTTP response codes, redirects, or kit fingerprints were provided, so further analysis of archived captures may be required to determine the full scope of the scam.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Informazioni forensi
Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo