mmt[.]airdropsalert[.]us
“Google”
mmt.airdropsalert.us — 内容不可用. 品牌冒充:Google; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 14/93 (ChainPatrol, alphaMountain.ai, BitDefender, Certego, CRDF); PhishDestroy score 92/100. 注册商: Dynadot.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain mmt.airdropsalert.us indicates it was actively impersonating Google as part of a cryptocurrency scam, as documented in threat intelligence records dated July 23, 2026. The domain, created on October 18, 2025, and registered through Dynadot LLC, resolved to the IP address 172.253.63.105, which is associated with AS15169 (Google LLC) in the United States. Despite the IP's legitimate ownership, the domain itself was flagged by 14 of 93 security vendors on VirusTotal and appeared on at least one security blocklist, specifically PhishDestroy. The domain used Cloudflare nameservers (brenna.ns.cloudflare.com and hassan.ns.cloudflare.com) and lacked an SSL certificate, which is atypical for legitimate services but common in low-effort phishing infrastructure.
The page title was explicitly set to 'Google,' aligning with the brand impersonation noted in the intelligence data. Gridinsoft assigned a trust score of 0/100, further supporting its classification as malicious. The domain was categorized as a crypto scam, though specific details about the scam mechanics (e.g., fake wallets, airdrop lures, or credential harvesting) are not available in the provided data. As of the report date, the domain was offline, though defenders should treat it as part of a broader pattern of Google-branded cryptocurrency fraud.
Defenders are advised to block the domain at the DNS or proxy level, monitor for related infrastructure (e.g., similar Cloudflare-hosted domains or Dynadot registrations), and correlate logs for connections to 172.253.63.105 during the domain's active period. While the IP is owned by Google, its use in this context does not indicate compromise of Google's infrastructure but rather potential abuse of shared hosting or misconfigured services. No additional HTTP response codes, redirects, or kit fingerprints were provided, so further analysis of archived captures may be required to determine the full scope of the scam.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。