bluefin[.]airdropalert[.]us
“Google”
bluefin.airdropalert.us — Контент недоступен. Олицетворение бренда: Google; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 17/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); Google Safe Browsing flagged; PhishDestroy score 95/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, bluefin.airdropalert.us, is identified as a high-risk brand impersonation threat specifically targeting Gmail users. The infrastructure is designed to mimic Google's login interface, as evidenced by the page title 'Google,' with the intent to harvest credentials or distribute malicious payloads. No drainer kit signatures were observed in initial scans, but the domain's design aligns with credential phishing campaigns commonly deployed against webmail services.
Technical indicators confirm the malicious nature of this domain. It was registered on October 19, 2025, through Dynadot LLC and currently resolves to the IP address 142.251.35.164, which is geolocated in the United States under AS15169 (Google LLC). Despite the IP's association with a legitimate provider, the domain itself is flagged by 17 out of 95 security vendors on VirusTotal. Google Safe Browsing classifies it as phishing, and it appears on at least one security blocklist. Notably, the domain lacks an SSL certificate, which is atypical for legitimate login portals and further indicates its fraudulent purpose.
As of the latest assessment, bluefin.airdropalert.us has been taken offline, likely due to enforcement actions or hosting provider intervention. However, the infrastructure may resurface under a different domain or IP address, given the transient nature of phishing campaigns. Users who interacted with this domain should immediately reset their credentials, enable multi-factor authentication, and monitor for unauthorized access. Organizations are advised to block the domain and associated IP at the network level, while security teams should investigate potential lateral movement or follow-up attacks originating from compromised accounts.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание