sym[.]airdropsalert[.]us
“Google”
证据摘要
Analysis of the domain sym.airdropsalert.us indicates elevated risk due to confirmed brand impersonation targeting Google. The domain was registered on October 18, 2025, through Dynadot LLC and resolves to the IP address 142.251.41.164, which is associated with AS15169 (Google LLC) in the United States. This alignment with Google’s infrastructure may have been exploited to lend credibility to the phishing operation, though the hosting context remains unverified. Nameservers are provided by Cloudflare (brenna.ns.cloudflare.com and hassan.ns.cloudflare.com), a common tactic to obscure origin and evade takedowns.
The domain lacks an SSL certificate, increasing susceptibility to interception and reducing user trust signals. The page title, explicitly labeled 'Google,' corroborates the brand impersonation claim. Gridinsoft assigns a trust score of 0/100, and the domain appears on at least one security blocklist. PhishDestroy has flagged it as malicious, and 12 of 93 security vendors on VirusTotal detect it as harmful, though the absence of additional context limits attribution to a specific threat actor or campaign.
The scam type is classified as a crypto scam, though no further details about the mechanics or payload are available. The domain was taken offline by the report date of July 23, 2026, but residual risk persists for users who may have interacted with it prior to deactivation. Defenders should monitor for related domains registered under the same registrar or utilizing identical nameserver patterns, particularly those leveraging Cloudflare or resolving to Google-owned IP ranges. Network-level blocking of 142.251.41.164 is recommended where feasible, alongside user education regarding crypto-related phishing lures impersonating major brands.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控