MALICIOUS — HIGH
Verificação de phishing e segurança de commoncheck.live
commoncheck[.]
The domain commoncheck.live was observed hosting a fake airdrop phishing page titled “Common | Airdrop”.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- Disponibilidade
- Conteúdo indisponível · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
commoncheck.live — Conteúdo indisponível (HTTP 502). Tipo de golpe: Airdrop Scam. Resumo das evidências: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); URLQuery 4 alerts; PhishDestroy score 65/100. Registrador: Name.com.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
The domain commoncheck.live was observed hosting a fake airdrop phishing page titled “Common | Airdrop”. The site was registered through Name.com, Inc. on February 21, 2026 and resolved to the IP address 185.107.74.113, which belongs to AS200430 owned by WEBO LLC and is geolocated to Sweden. Four name servers—ns2dqr.name.com, ns4cfn.name.com, ns3gxy.name.com, and ns1crv.name.com—were configured for the domain. No TLS certificate was presented when the site was accessed, indicating that communications were unencrypted.
The page was flagged by the PhishDestroy blocklist and appears on a single security blocklist at the time of analysis. VirusTotal reported that the domain was scanned by ninety‑three antivirus and URL‑reputation engines; none of the engines raised a detection, although the absence of a flag does not constitute validation of safety. The site is currently offline, and no HTTP response codes or content were captured after takedown. The evidence suggests an opportunistic phishing campaign that leveraged the popularity of airdrop incentives to lure victims, but the limited infrastructure footprint—single IP, single registrar, and a short lifespan—makes attribution difficult.
Defenders should continue to monitor the IP address 185.107.74.113 and the associated autonomous system for any re‑use, enforce outbound filtering for URLs containing “commoncheck.live”, and add the domain to internal blocklists. Since the page title references an airdrop, organizations handling cryptocurrency assets should alert users to the risk of unsolicited airdrop offers, especially those that request credentials or personal information. Ongoing threat‑intelligence feeds should be consulted for any resurgence of the domain or related infrastructure, and any future observations should be correlated with the registrar Name.com, Inc. and the observed name‑server pattern for rapid detection.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura dos dados12 recorded checks
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS0 Zero | commoncheck.live |
malicious | Sinkholed |
| Quad9 DNS | afumyacvizccbvqvzkoxuqrhyuaqopcopwfygjv.com |
malicious | Sinkholed |
| Hagezi Threat Feed | afumyacvizccbvqvzkoxuqrhyuaqopcopwfygjv.com |
malicious | Sinkholed |
| DNS0 Zero | afumyacvizccbvqvzkoxuqrhyuaqopcopwfygjv.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.