ton[.]airdropsalert[.]us
“Google”
ton.airdropsalert.us — Контент недоступний (HTTP 502). Уособлення бренду: Google; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 12/93 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 86/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of ton.airdropsalert.us indicates a confirmed brand impersonation campaign targeting Google, classified as a crypto scam. The domain, registered on October 18, 2025, through Dynadot LLC, currently resolves to IP 142.251.163.105, hosted under AS15169 (Google LLC) in the United States. Infrastructure review reveals the domain uses Cloudflare nameservers (brenna.ns.cloudflare.com, hassan.ns.cloudflare.com) but lacks an SSL certificate, increasing exposure to interception risks. The page title 'Google' directly aligns with the reported brand target, suggesting an intent to deceive users into believing the site is affiliated with Google.
Detection data shows the domain appears on one security blocklist (PhishDestroy) and is flagged by 12 of 93 security vendors on VirusTotal, confirming malicious classification. Gridinsoft assigns a trust score of 0/100, further corroborating its fraudulent nature. As of July 23, 2026, the domain is offline, though historical records indicate it was actively serving content prior to takedown. The absence of an SSL certificate and reliance on Cloudflare nameservers are consistent with low-effort phishing infrastructure, though the use of Google LLC’s IP range may reflect attempts to evade reputation-based filtering.
Defenders should treat this domain as compromised and block all resolutions at the DNS level. Given the crypto scam classification, monitor for related domains using the 'airdropsalert' subdomain pattern or similar Google-themed lures. No evidence links this domain to a specific phishing kit or additional payloads, so further forensic analysis of captured traffic or historical snapshots would be required to determine exact attack vectors. The domain’s registration age (9 months) suggests it may have been part of a longer-term campaign, warranting retrospective log reviews for prior exposure.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога