spaceandtime[.]airsdropsalert[.]lol
“Google”
spaceandtime.airsdropsalert.lol — Контент недоступен (HTTP 502). Олицетворение бренда: Google; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 2/95 (ChainPatrol, SOCRadar); PhishDestroy score 56/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain spaceandtime.airsdropsalert.lol is currently offline and has been taken down by the PhishDestroy takedown service. Registration data shows the domain was created on 5 November 2025 through Dynadot LLC, and the authoritative nameservers are brenna.ns.cloudflare.com and hassan.ns.cloudflare.com, indicating the use of Cloudflare’s DNS infrastructure. DNS resolution points to IP address 142.250.74.196, which belongs to AS15169 owned by Google LLC and is geolocated in the United States. No SSL certificate is presented for the host, meaning HTTPS connections would be unencrypted if the site were reachable.
The page title returned from the site, when it was online, was simply "Google," matching the declared brand target of Google and confirming the classification as a brand‑impersonation campaign. Reputation services show a Gridinsoft trust score of 0 out of 100, and the domain appears on one external security blocklist, reinforcing its malicious intent. VirusTotal analysis recorded detections from two of ninety‑five scanning engines, providing additional corroboration of suspicious activity. The limited detection footprint suggests the site was short‑lived, likely intended for a narrow phishing window.
Uncertainty remains regarding the specific phishing kit or payload used, as no further content analysis is available. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any resurgence of the same host header or similar sub‑domains, and verify that internal users are aware of the impersonation attempt targeting Google credentials. Incident response teams should also update threat‑intel feeds with the observed indicators of compromise, including the domain name, registration details, IP address, and the two VirusTotal detections, to aid in rapid correlation of future attempts.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: airsdropsalert.lol
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain airsdropsalert.lol behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание