fil[.]airdropsalert[.]bar
“Google”
fil.airdropsalert.bar — Контент недоступен. Олицетворение бренда: Google; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 16/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 95/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain fil.airdropsalert.bar was observed hosting a fraudulent page that presents the generic title “Google”. The site employed the Cloudflare authoritative nameservers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com, and the DNS resolution pointed to 142.250.181.228, an IP address owned by Google LLC (AS15169) located in the United States. The use of a legitimate Google‑owned IP can aid evasion of network‑level filters. The domain was registered on 20 October 2025 through Dynadot LLC and lacks an SSL/TLS certificate, indicating that the service was delivered over plain HTTP.
Google Safe Browsing classified the URL as “social engineering”, confirming that the content was intended to deceive users into trusting the brand. Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on a single security blocklist. VirusTotal reports that 16 of 95 scanning engines flagged the domain, reinforcing the malicious assessment. PhishDestroy has already taken the domain offline, and its current status is listed as offline.
The primary uncertainty is the exact payload or credential‑harvesting mechanism, as no page content beyond the title has been disclosed. Defenders should continue to block the domain at DNS and proxy layers, ensure that outbound traffic to the associated IP is inspected, and monitor for any future re‑registration attempts that reuse the same subdomain pattern. Adding the domain to internal blocklists and correlating any logs that reference the Cloudflare nameservers can help detect residual activity. Given the high‑risk classification, continuous monitoring of related brand‑impersonation campaigns is advised.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: airdropsalert.bar
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain airdropsalert.bar behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание