sophon[.]portal-drops[.]icu
“Google”
sophon.portal-drops.icu — 内容不可用 (HTTP 502). 品牌冒充:Google; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 6/95 (ChainPatrol, alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker); PhishDestroy score 68/100. 注册商: Dynadot.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The site sophon.portal-drops.icu presented a page titled "Google" and was identified as an impersonation scam targeting the Gmail brand. This threat involved deceiving users into believing they were interacting with a legitimate Google login page, potentially to harvest credentials or sensitive information.
Technical analysis shows the domain was flagged by 6 out of 95 VirusTotal vendors, with detections from ChainPatrol, alphaMountain.ai, CRDF, CyRadar, and Forcepoint ThreatSeeker. It was registered through Dynadot LLC on 2025-10-20, hosted on IP 142.250.186.132 (US, AS15169 Google LLC), and used nameservers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com. No SSL certificate was present.
The site is currently offline. With a GridinSoft trust score of 0/100 and a DOM risk score of 25, the risk level is considered moderate due to the impersonation of a well-known brand and the presence of multiple security vendor flags, though it is no longer active.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
SHORTDOT 域名区 · 公开证据
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Registration: portal-drops.icu
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For the registrable domain portal-drops.icu behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。