scr[.]airdropalert[.]us
“Google”
scr.airdropalert.us — Контент недоступен (HTTP 502). Олицетворение бренда: Google; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 15/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); PhishDestroy score 95/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain scr.airdropalert.us was registered on October 19, 2025 through Dynadot LLC and is currently taken offline. DNS resolution points to the IP address 142.251.111.105, which belongs to AS15169 Google LLC and is geolocated in the United States. The domain uses Cloudflare nameservers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com, but no TLS certificate is presented, indicating that the site was served over plain HTTP when it was active. The page title returned by the server is "Google," matching the declared brand target of Google and confirming a brand‑impersonation motive. Threat intelligence categorises the activity as a crypto‑scam, though the exact payload or lure was not captured in the available data.
Multiple security controls have flagged the domain. It appears on one external blocklist and is listed by PhishDestroy as malicious. The Gridinsoft trust score is 0 out of 100, reflecting extreme risk. VirusTotal analysis shows that 15 of 93 scanning engines flagged the domain, reinforcing the suspicion of malicious intent. The combination of a brand‑matching page title, lack of encryption, and association with a known crypto‑scam pattern suggests that the domain was used to lure victims into fraudulent cryptocurrency transactions.
Defenders should continue to block scr.airdropalert.us at network perimeter and DNS filtering layers, monitor for any residual traffic to the associated IP address, and consider adding the IP to reputation lists. Given the Cloudflare name server configuration, future sub‑domains could be spun up under the same authority; continuous watch of the registrar and name server records is advised. Incident response teams should also review any internal logs for connections to the domain or its IP during the active window, and ensure that endpoint protection solutions are updated to reflect the VirusTotal detections. The offline status does not guarantee cessation of activity, so ongoing vigilance is recommended.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание