soph[.]airdropalerts[.]bond
“Google”
soph.airdropalerts.bond — Контент недоступний (HTTP 502). Уособлення бренду: Google; Тип шахрайства: Fake Airdrop. Зведення доказів: VirusTotal 11/95 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 83/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, soph.airdropalerts.bond, was registered on 14 October 2025 through Dynadot LLC and is currently listed as offline. DNS resolution points to IP address 142.250.185.100, which belongs to AS15169 Google LLC and resolves to a location in the United States. No SSL certificate is presented for the host, indicating that the site does not offer HTTPS protection. The authoritative name servers are brenna.ns.cloudflare.com and hassan.ns.cloudflare.com, both associated with Cloudflare's DNS infrastructure. The page title returned by the server is “Google”, matching the declared impersonation of the Google brand.
The domain is classified as a “Fake Airdrop” scam and is reported to impersonate Google, a technique commonly used to lure victims into providing credentials or personal information under the pretense of receiving an airdrop reward. Security telemetry shows that the domain appears on one blocklist and has been flagged by PhishDestroy. VirusTotal analysis reports that 11 of 95 scanning engines label the domain as malicious, reinforcing the suspicion of fraudulent activity. At present no HTTP response body or login form has been captured, so the exact content of the fraudulent page cannot be confirmed. The lack of an SSL certificate also hampers any attempt to analyze encrypted traffic.
While the site is offline, its infrastructure—particularly the use of Google‑owned IP space and Cloudflare DNS—can be leveraged by threat actors to increase perceived legitimacy. Defenders should continue to block the domain at the network perimeter, monitor DNS queries for the associated name servers, and add the IP address to reputation lists. Correlation with the domain name is essential because the IP is owned by Google and may generate false positives if used elsewhere. Additional investigation of any historical HTTP responses or payloads, if available, would help confirm the exact phishing tactics employed.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ЗОНА SHORTDOT · ПУБЛІЧНІ ДОКАЗИ
.bond
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Registration: airdropalerts.bond
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain airdropalerts.bond behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога