cetus[.]airdropalert[.]us
“Google”
Сводка доказательств
This domain, cetus.airdropalert.us, was identified as a high-risk brand impersonation site targeting Google, specifically designed to facilitate a cryptocurrency scam. Registered on October 19, 2025, through Dynadot LLC, the domain has since been taken offline, though infrastructure analysis reveals key indicators of malicious activity. The page title explicitly displayed 'Google,' aligning with the known scam type of crypto fraud. No SSL certificate was present, increasing the likelihood of unencrypted data transmission and further exposing potential victims to interception risks. Infrastructure analysis shows the domain resolved to the IP address 142.250.176.196, which is associated with AS15169 (Google LLC) in the United States.
While the IP itself is linked to a legitimate provider, the domain's use of Cloudflare nameservers (brenna.ns.cloudflare.com and hassan.ns.cloudflare.com) suggests an attempt to obscure its origin and evade basic detection mechanisms. Google Safe Browsing flagged the domain for social engineering, a classification consistent with phishing or scam operations. Additionally, the domain appears on at least one security blocklist, and 11 of 93 security vendors on VirusTotal detected it as malicious, though the absence of further context limits the granularity of these detections. Defenders should treat this domain as a confirmed threat, particularly given its association with cryptocurrency fraud.
The lack of SSL, combined with the use of Cloudflare infrastructure and a registration through a low-friction registrar, aligns with common tactics used in scam campaigns. While the domain is currently offline, organizations should monitor for re-registration or similar domains under the airdropalert.us parent structure. Network-level blocking of the resolved IP during its active period is recommended, along with retrospective analysis of logs for connections to cetus.airdropalert.us or related subdomains.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Криминалистическая аналитика
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание