morpho[.]portal-drops[.]sbs
“Google”
Riepilogo delle prove
This site, morpho.portal-drops.sbs, is an impersonation scam targeting users of the Gmail brand. The page was titled "Google" and the scam type is impersonation, posing as a legitimate Google login page to steal credentials. The threat is credential theft through a fraudulent Gmail authentication portal.
Technical evidence shows the domain was created on 2025-10-20 and registered with Dynadot LLC. It resolves to IP address 142.250.65.228, hosted by AS15169 Google LLC in the United States. The site has no SSL certificate. VirusTotal reports 4 detections out of 95 scanners, with blocklisting by ChainPatrol, alphaMountain.ai, SOCRadar, and Webroot, and it appears on 1 blocklist. Nameservers are brenna.ns.cloudflare.com and hassan.ns.cloudflare.com.
The domain is currently down/offline, with a DOM risk score of 10, indicating a critical threat level despite its inactive status. Given the low detection rate and lack of SSL, this site represents a direct impersonation risk for credential harvesting.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ZONA SHORTDOT · PROVE PUBBLICHE
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Registration: portal-drops.sbs
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain portal-drops.sbs behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Informazioni forensi
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo