MALICIOUS — CRITICAL
asterpool[.]top
Analysis of the domain asterpool.top indicates it was a high-risk phishing site targeting users with a fake Aster airdrop scam.
- VirusTotal
- 16/91
- Blocklists
- 3 · MetaMask, ScamSniffer
- Disponibilidade
- Conteúdo indisponível · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
asterpool.top — Conteúdo indisponível (HTTP 502). Representação da marca: Genericcrypto; Tipo de golpe: Fake Airdrop. Resumo das evidências: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 2 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 95/100. Registrador: NiceNIC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
asterpool.top fake Aster airdrop scam – high-risk phishing domain
Analysis of the domain asterpool.top indicates it was a high-risk phishing site targeting users with a fake Aster airdrop scam.
Analysis of the domain asterpool.top indicates it was a high-risk phishing site targeting users with a fake Aster airdrop scam. The domain, created on March 11, 2026, resolved to IP 188.114.97.3, hosted on Cloudflare's infrastructure (AS13335) in the United States. Nameservers bristol.ns.cloudflare.com and zac.ns.cloudflare.com were configured, and the SSL certificate was issued by Let's Encrypt (serial E8). The site's page title, 'Aster airdrop,' directly aligned with its classification as an airdrop scam, a common tactic to deceive cryptocurrency users into disclosing credentials or transferring funds. The domain appeared on four security blocklists and was actively blocked by PhishDestroy, MetaMask, ScamSniffer, and SEAL, confirming its malicious intent.
VirusTotal detections from 16 of 91 security vendors further validated its classification as a phishing threat. The registrar, NICENIC INTERNATIONAL GROUP CO., LIMITED, has been associated with other fraudulent domains, though no direct attribution to this specific campaign is confirmed. Gridinsoft assigned a trust score of 0/100, reinforcing its high-risk status. As of July 23, 2026, the domain is offline, but defenders should treat any future resolution or reappearance as malicious.
Network-level blocking of 188.114.97.3 and monitoring for related domains using the same registrar or Cloudflare nameservers is recommended. The use of a Let's Encrypt certificate does not indicate legitimacy, as phishing sites frequently exploit free SSL providers to appear trustworthy. No additional brand impersonation or kit details beyond the 'Airdrop Scam' classification were provided, so the exact mechanics of the phishing flow remain unconfirmed. Organizations should correlate this domain with any recent user reports of airdrop-related phishing attempts.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura dos dados12 recorded checks
Inteligência de segurança de rede Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | asterpool.top |
malicious | Sinkholed |
| DNS4EU | asterpool.top |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-06 03:46:08 UTC
Análise do VirusTotal
Evidências e relatórios externosIndependent lookups and source reports
PD-20260622-54BEAA Recipient: abuse@nic.top Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.