ton[.]airsdropsalerts[.]click
“Google”
ton.airsdropsalerts.click — Контент недоступен (HTTP 502). Олицетворение бренда: Google; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 9/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CRDF, CyRadar); PhishDestroy score 77/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain ton.airsdropsalerts.click was observed as an offline site that leveraged a brand‑impersonation technique targeting Google users. Registration data shows the domain was created on 07 November 2025 through Dynadot LLC, and DNS resolution points to the IP address 142.250.185.132, which belongs to AS15169 Google LLC and is geolocated in the United States. No TLS certificate was presented for the host, indicating that HTTPS was not configured at the time of analysis. The authoritative name servers are brenna.ns.cloudflare.com and hassan.ns.cloudflare.com, both operated by Cloudflare.
Threat intelligence feeds have flagged the domain as a brand‑impersonation case. VirusTotal analysis recorded detections by nine of the ninety‑five scanning engines that evaluated the host. The site appears on a single security blocklist and has been actively blocked by the PhishDestroy mitigation service. The page title returned by the HTTP response is "Google," matching the claimed brand target, and the domain is explicitly listed as impersonating Google.
Current evidence suggests the infrastructure was deliberately pointed at a legitimate Google IP range, likely to increase trust and evade simple IP‑based blocking. The lack of an SSL certificate, combined with the offline status, may indicate a temporary testing phase or a takedown after detection. Defenders should continue to block the domain at the DNS and URL filtering layers, monitor for any re‑registration attempts, and consider adding the associated IP address to network‑level deny lists pending further verification. Ongoing surveillance of the Cloudflare name servers for new sub‑domains that reference similar branding patterns is advised, as threat actors often reuse these hosting configurations.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: airsdropsalerts.click
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain airsdropsalerts.click behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание