sca[.]airdrpsalert[.]click
“airdrpsalert.click | 504: Gateway time-out”
sca.airdrpsalert.click — Контент недоступен (HTTP 502). Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 8/95 (ChainPatrol, CRDF, CyRadar, Seclookup, SOCRadar); PhishDestroy score 74/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
sca.airdrpsalert.click was registered on 26 October 2025 through Dynadot LLC. The domain resolves to the IP address 188.114.96.3, which belongs to AS13335 (Cloudflare, Inc.) and is geolocated in the United States. DNS resolution is provided by the Cloudflare authoritative nameservers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com. No TLS certificate is presented; HTTP requests return a 504 Gateway‑time‑out page title that simply repeats the domain name and the error code, indicating that the site is currently offline. Threat intelligence correlates the domain with a credential‑phishing campaign that leverages an “Airdrop Scam” kit.
Eight of ninety‑five VirusTotal scanners have flagged the domain as malicious, and it appears on one external blocklist. PhishDestroy has already blocked the host, and Gridinsoft assigns it a trust score of 0 / 100, reinforcing the malicious assessment. The presence of the kit suggests the operator may be attempting to harvest cryptocurrency‑related credentials or private keys, although the exact payload has not been captured because the site is not serving content. The available evidence confirms a malicious infrastructure that uses Cloudflare’s network to hide the origin server, a common tactic for fast‑flux or abuse‑resistant phishing operations.
Because the domain is presently offline, active probing cannot reveal additional indicators such as redirect URLs, form fields, or malicious scripts. Defenders should continue to deny any DNS resolution to 188.114.96.3 for this host, add sca.airdrpsalert.click to internal blocklists, monitor for re‑registration or resurrection of the domain, and watch for similar patterns in newly observed Airdrop‑kit domains. Ongoing vigilance is recommended, especially for users who may receive unsolicited airdrop invitations that request private keys or login credentials.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: airdrpsalert.click
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain airdrpsalert.click behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание