leagueoftraders-airdrop[.]io
“leagueoftraders-airdrop.io”
leagueoftraders-airdrop.io — Gizlenmiş · ulaşılabilir. Marka kimliğine bürünme: Google; Dolandırıcılık türü: Tech Support Scam. Kanıt özeti: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); 4 external blocklist matches; cloaking observed; PhishDestroy score 93/100.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain leagueoftraders-airdrop.io was registered on February 21, 2026 and is currently taken offline, but historical activity indicates a targeted brand‑impersonation campaign against Google. The site presented the page title leagueoftraders-airdrop.io, matching the domain name, and employed a publicly trusted Sectigo RSA Domain Validation Secure Server certificate, which can lend superficial credibility to unsuspecting victims. Infrastructure analysis shows the domain resolved to IP address 185.105.33.106, an address allocated to AS43927 HOSTERION SRL in Great Britain. The IP has been listed on five security blocklists and the domain appears on multiple reputable blocking feeds, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura.
Reputation scoring from Gridinsoft assigns a zero‑out‑of‑one‑hundred trust rating, reinforcing the malicious classification. VirusTotal scans report that two of ninety‑three security vendors flagged the domain, suggesting at least a minimal detection consensus among scanners. The observed scam kit is labeled “Airdrop Scam,” while the declared scam type is a Tech Support Scam, both of which are commonly leveraged to harvest credentials or extort payments under the guise of a Google‑related support request. Evidence confirms the domain impersonates Google, a high‑value target for credential harvesting.
What remains unknown is the exact content delivered to end users, the specific phishing workflow, and whether any payloads were deployed, as no direct page capture is available. Defenders should continue to block the domain and associated IP address across perimeter and DNS filters, monitor for any resurgence of the host on other registrars, and consider adding the ASN to threat‑intelligence watchlists. Continuous verification of the domain’s status through passive DNS and threat‑feed updates is recommended to catch any re‑activation attempts.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin