klima[.]airsdropalert[.]click
“Google”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
This domain is flagged for elevated-risk brand impersonation targeting Gmail users. The threat involves a fake login portal designed to harvest credentials by mimicking Google's authentication interface. Analysis indicates the domain was created to deceive users into entering sensitive account information under the guise of a legitimate service. Infrastructure analysis reveals the domain klima.airsdropalert.click was registered on November 05, 2025, through Dynadot LLC. It resolves to IP 216.58.206.68, geolocated in Germany under AS15169 (Google LLC), though this appears to be a misdirection or abuse of hosting infrastructure. The page title 'Google' further reinforces the impersonation attempt. The domain is currently offline but was detected by 14 out of 95 security vendors on VirusTotal, including a listing on one security blocklist (PhishDestroy). The SSL certificate is issued by Google Trust Services (WE1), which may have been exploited to lend false legitimacy to the phishing page. Mitigation steps for this specific threat type include immediate blocking of the domain and associated IP at the network perimeter. Organizations should deploy email filtering rules to quarantine messages containing links to klima.airsdropalert.click or similar impersonation domains. End-users should be educated on verifying URL authenticity before entering credentials, particularly for services like Gmail. Security teams are advised to monitor for credential reuse attempts, as harvested logins may be leveraged in follow-on attacks. Given the domain's recent creation and offline status, continuous monitoring for re-emergence or related infrastructure is recommended.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Registration: airsdropalert.click
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain airsdropalert.click behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of klima.airsdropalert.click · checked Mar 2, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin