gov-aerodrome[.]org
“Aerodrome Finance”
gov-aerodrome.org — Контент недоступен. Олицетворение бренда: Genericcrypto. Сводка доказательств: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; Google Safe Browsing flagged; Spamhaus DBL_PHISH; PhishDestroy score 92/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain gov-aerodrome.org was observed hosting a site with the page title “Aerodrome Finance”. The domain was registered on 06 December 2025 through Dynadot LLC and is currently taken offline. DNS resolution points to IP 104.21.53.158, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The authoritative name servers are alexa.ns.cloudflare.com and randall.ns.cloudflare.com, both Cloudflare‑operated. No TLS certificate was presented, indicating the site was served over plain HTTP or that the certificate was missing at the time of analysis.
Reputation services rate the domain poorly: Gridinsoft assigns a trust score of 0 out of 100, and Google Safe Browsing flags the URL for social‑engineering content. VirusTotal reports that 14 of 95 scanned security vendors flagged the domain, demonstrating a moderate level of detection across independent scanners. The domain appears on a single external blocklist and has been explicitly blocked by the PhishDestroy service, reinforcing the assessment that it is being used for malicious purposes. The available evidence points to a generic phishing operation that likely attempts to harvest credentials or financial information under the guise of an “Aerodrome Finance” portal.
Because the site is already offline, immediate mitigation focuses on preventing future resolution and credential reuse. Defenders should add the domain and its associated IP address to internal block lists, monitor for any CNAME or DNS changes that point to alternative hosting, and enforce strict email filtering rules for messages that reference “Aerodrome Finance” or similar phrasing. Continuous re‑query of reputation feeds is advised, as the threat actor may register new domains using the same naming pattern. At present, the lack of a TLS certificate, the low trust score, and multiple independent detections constitute sufficient evidence to classify the domain as high‑risk and to treat any related traffic as malicious.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание