flx[.]airdrpsalerts[.]click
“Google”
flx.airdrpsalerts.click — 未验证. 品牌冒充:Google; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 13/91 (ChainPatrol, BitDefender, CRDF, CyRadar, ESET); PhishDestroy score 89/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain flx.airdrpsalerts.click indicates it was actively engaged in credential phishing targeting Google users. The domain, created on February 21, 2026, resolved to the IP address 192.178.155.103, hosted under AS15169 (Google LLC) in the United States. Despite the hosting infrastructure association with Google, the domain itself was flagged for brand impersonation, specifically mimicking Google, as evidenced by the page title 'Google' and its classification as a credential phishing scam. The domain has since been taken offline, though its prior activity was detected and blocked by PhishDestroy, and it appears on at least one security blocklist.
Gridinsoft assigned a trust score of 0/100, reinforcing its high-risk classification. VirusTotal scans identified the domain as malicious by 2 of 95 security vendors, though this represents a limited detection scope. The SSL certificate was issued under the identifier WR2, which does not provide additional trust indicators.
Defenders should treat this domain as a confirmed phishing threat, particularly for credential harvesting targeting Google services. Historical resolution data, SSL certificate details, and detection timestamps should be incorporated into threat intelligence feeds to prevent future access or re-emergence. No additional page content or phishing kit details are currently available for further classification.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。