MALICIOUS — CRITICAL
Перевірка домену aerodromeauthorization.com на фішинг і безпеку
aerodromeauthorization[.]
The domain aerodromeauthorization.com is currently active and classified as a high‑risk brand‑impersonation operation targeting the Aerodrome brand.
- VirusTotal
- 5/91
- Blocklists
- 4 · ScamSniffer, Polkadot
- Доступність
- Контент недоступний · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
aerodromeauthorization.com — Контент недоступний (HTTP 404). Уособлення бренду: Aerodrome; Тип шахрайства: Impersonation. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 4 external blocklist matches; PhishDestroy score 85/100. Реєстратор: Ultahost.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
The domain aerodromeauthorization.com is currently active and classified as a high‑risk brand‑impersonation operation targeting the Aerodrome brand. The site presents a page titled “SECURITY CHECK”, which is commonly used in credential‑harvesting flows. The domain was registered on August 17 2025 through Ultahost, Inc., within the typical lifecycle of malicious infrastructure.
Infrastructure analysis shows the domain resolves to IP address 82.25.35.148, which belongs to AS21859 operated by Zenlayer Inc. The IP geolocates to the United Kingdom. DNS resolution is served by Cloudflare nameservers addilyn.ns.cloudflare.com and rudy.ns.cloudflare.com, suggesting the attackers are leveraging Cloudflare’s CDN to hide origin infrastructure. No TLS certificate is associated with the domain, and the HTTP response is a 302 redirect, indicating active redirection behavior.
Reputation services flag the domain as malicious: Scamadviser assigns a trust score of 26 / 100, Gridinsoft reports 0 / 100, and the domain appears on five security blocklists, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. VirusTotal indicates that 1 of 95 security vendors has flagged the domain, providing limited but corroborating evidence. The combination of a brand‑impersonation label, lack of encryption, and redirection behavior aligns with typical credential‑stealing campaigns.
Defenders should treat aerodromeauthorization.com as hostile. Immediate actions include adding the domain and its resolving IP to block lists, configuring DNS sinks or firewall rules to prevent connection attempts, and monitoring for similar registration patterns. Because the exact content beyond the page title has not been publicly disclosed, analysts should continue to sample the site for potential payloads or credential collection mechanisms. Ongoing observation of the associated Cloudflare nameservers may reveal additional malicious domains that share the same infrastructure.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Обсяг даних13 recorded checks
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.