aiairdroprush[.]com
Перевірка домену aiairdroprush.com на фішинг і безпеку
“Aiairdrop Rush”
aiairdroprush.com — Контент недоступний (HTTP 502). Уособлення бренду: Across; Тип шахрайства: Fake Airdrop. Зведення доказів: VirusTotal 5/95 (alphaMountain.ai, BitDefender, G-Data, Kaspersky, Seclookup); PhishDestroy score 65/100. Реєстратор: Cosmotown.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain aiairdroprush.com, observed on July 23 2026, indicates that it was used to deliver a fake airdrop campaign impersonating the brand “across”. The site employed the publicly‑available “Airdrop Scam” phishing kit, as identified by threat intelligence sources. The page title returned by the server was “Aiairdrop Rush”, which aligns with the advertised scam theme. The domain was registered on 25 March 2025 through Cosmotown, Inc. and is served by the four LyteHosting name servers (dns1.lytehosting.com, dns2.lytehosting.com, dns3.lytehosting.com, dns4.lytehosting.com). DNS resolution points to IP address 163.61.188.222, which belongs to ASN 153568 (NEW DHAKA HARDWARE) and is geolocated in the United States.
No TLS certificate was presented, meaning the site operated over plain HTTP only. The hosting infrastructure has been listed on a single security blocklist; PhishDestroy currently blocks the domain. VirusTotal scans show that five of ninety‑five antivirus engines flagged the domain as malicious, reinforcing the suspicion of malicious activity. The domain’s current HTTP status is offline, indicating that the malicious content has been removed or the site has been taken down. Uncertainty remains regarding the exact content that was served before takedown, as no live page was captured.
Additionally, the limited blocklist presence (only one listing) suggests that broader community detection may be delayed. Defenders should add the domain to internal blocklists, monitor the associated IP and name‑server range for further abuse, and consider the ASN 153568 as a potential vector for related campaigns. Continuous observation of Cosmotown‑registered domains and LyteHosting name servers is advised, as they have been used in prior phishing operations. Organizations that reference the “across” brand should educate users about unsolicited airdrop offers and enforce strict URL verification to mitigate credential harvesting attempts.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога