الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 13. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

5ww-umb[.]com

“UMB Direct Login”

حكم التهديد حرجة 93/100 درجة الأدلة
التوفر خطأ في الخادم آخر استجابة مخزنة كانت غير حاسمة
اكتشافات VirusTotal: 13/91 Spamhaus DBL: DBL_SPAM URLQuery threat systems: 4 alerts انتحال العلامة التجارية: Umbfc المجال الصغير: 12 عمره أيام
31/07/2026 Umbfc 1 Report Sent

ملخص الأدلة

حرج
Evidence score
93/100

Analysis of 5ww-umb.com shows that the domain was registered on July 30 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently resolving to the IPv4 address 87.251.64.218. The domain is listed on one public security blocklist and has been explicitly blocked by the PhishDestroy sinkhole, indicating that threat‑intelligence feeds have already flagged it as malicious. VirusTotal reports that 13 of 91 scanned security vendors flag the domain as malicious, reinforcing the suspicion of phishing activity.

The domain is served by the authoritative name servers ns3.my-ndns.com and ns4.my-ndns.com, which are commonly observed in other malicious campaigns. The infrastructure is classified as high‑risk and remains active at the time of this report (July 31 2026). No public SSL certificate details, HTTP response codes, page title, or Safe Browsing/OTX entries are currently available for this host, limiting the depth of content‑level analysis.

Defenders should immediately add 5ww-umb.com to network‑level deny lists, block traffic to 87.251.64.218, and monitor for any look‑alike domains registered by the same registrar. Continuous re‑scanning on VirusTotal and inclusion in endpoint URL filtering policies are recommended to capture any future changes in detection status. Because the domain is newly created and already exhibits multiple indicators of compromise, proactive blocking is advised to prevent credential harvesting or other phishing‑related compromise.

لقطة الأدلة المرسلة

أُرسل
سجلات الدفتر
1
معرّف القضية
PD-20260731-98602D
عنوان الصفحة الملتقطة
UMB Direct Login
ملف PDF
دليل PDF
النص الكامل للدليل
Registrar: NICENIC International Group Co., Limited (Hong Kong (China))
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
VirusTotal
VirusTotal
13 det.
URLQuery
URLQuery
4 threat alerts
رادار CF
ضار
شهادة TLS
Let's Encrypt
العمر
12d Very New!
الحالة المرصودة
خطأ في الخادم HTTP 502
PhishDestroy
قائمة الإتلاف
مدرج
Reports Sent
1

Data Coverage

VirusTotal 13 / 91 URLQuery 4 threat-system alerts PhishStats لم يتم التحقق منها OTX no community references رادار CF provider verdict: malicious URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 89d WHOIS 12d old لقطة شاشة 4 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكاتRegistrar context
Threat Detection Systems 4 alerts
Detection System Indicator Verdict Alert
DigiCert UltraDNS 5ww-umb.com malicious Sinkholed
DNS4EU 5ww-umb.com malicious Sinkholed
OpenDNS 5ww-umb.com phishing Phishing Block
Cloudflare DNS 5ww-umb.com malicious Sinkholed
CF Cloudflare Radar Verdict ضار
DGA Domains Security Risks Security threats Phishing Phishing
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
14/15

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

أدلة النتيجة المحفوظة

النتيجة وإسناد الإزالة

النتيجة
held
التوفر
unreachable
السبب
registrar_client_hold
الجهة الفاعلة
NICENIC INTERNATIONAL GROUP CO., LIMITED
الآلية
client_hold
درجة الثقة
95%
أول رصد
أحدث رصد

وقت التعطل التقديري

الوقت حتى تعذر الوصول: 0 h

SHA-256 للدليل 0407da6e4725

المخطط الزمني للاكتشاف

  1. أول تسجيل

    أول قيمة محفوظة: يمكن الوصول إليه

  2. التوفر

    أول قيمة محفوظة: DNS غير نشط

    f93a11f87e4d
  3. التوفر

    DNS غير نشط ← غير معروف

    93c09bebe445
  4. حالة النطاق

    يمكن الوصول إليه ← يتعذر الوصول إليه

  5. التوفر

    غير معروف ← DNS غير نشط

    2b6f08745b7a
  6. التوفر

    DNS غير نشط ← محتجز

    1e1236f92a83
  7. التوفر

    محتجز ← DNS غير نشط

    f52d526b76a1
  8. التوفر

    DNS غير نشط ← غير معروف

    b5da07eec389
  9. التوفر

    غير معروف ← محتجز

    5b5e620d6a00
  10. التوفر

    محتجز ← غير معروف

    91516bd37213
عرض الكل (11)
  1. التوفر

    غير معروف ← DNS غير نشط

    6dfe9145995c
  2. التوفر

    DNS غير نشط ← محتجز

    caadf4b27a37
  3. التوفر

    محتجز ← DNS غير نشط

    641ed81dc4d5
  4. التوفر

    DNS غير نشط ← غير معروف

    350db129b5a3
  5. التوفر

    غير معروف ← محتجز

    32306c87ae10
  6. التوفر

    محتجز ← غير معروف

    463287fd1cd9
  7. التوفر

    غير معروف ← DNS غير نشط

    d0b7046e8c2f
  8. التوفر

    DNS غير نشط ← محتجز

    5e633f94cf7a
  9. التوفر

    محتجز ← DNS غير نشط

    ca9ed662b468
  10. التوفر

    DNS غير نشط ← غير معروف

    46ab10666cc1
  11. التوفر

    غير معروف ← محتجز

    0407da6e4725

بلاغات المجتمع

لم يبلّغ عنه أي عضو في المجتمع؛ شوهد أول مرة في 31/07/2026

عناوين URL الفريدة المبلغ عنها
1

لقطة محفوظة

عنوان الصفحة
UMB Direct Login
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 89 days

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: Umbfc report ↗
الخادم / ASN nginx/1.30.2 · AS200730 ISAEV Igor
سمعة عنوان IP IP abuse confidence 0/100 1 report checked 31/07/2026
مسجّل النطاق NiceNIC RU(RU) PhishDestroy Investigation
جهة الإبلاغ عن إساءة الاستخدامabuse@nicenic.net, abuse@novahost.kz
البحث في قاعدة بيانات WHOISICANN RDAP لـ 5ww-umb.com →
عنوان IP 87.251.64.218 PL
الموقع الجغرافيPL Warsaw, PL
الشبكةAS200730 · Isaev
التسجيلتم إنشاؤه 30/07/2026 (12d · Very New!) Expires 30/07/2027
حالة HTTP502 Error
Elapsed Since First Report 6 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: خطأ في الخادم.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف31/07/2026
Submitted URLhttp://5ww-umb.com/
خوادم الأسماءns3.my-ndns.comns4.my-ndns.com
بصمة TLS
رصد TLSصالح منذ 30/07/2026فُحص في 31/07/2026
Favicon Hash
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.

التقنيات

حُدّدت تقنية واحدة عالية الثقة

Nginx
Cloudflare Radar
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

13 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed First positive detection
alphaMountain.ai
BitDefender
CRDF
ESET
Emsisoft
Fortinet
G-Data
LevelBlue
Lionic
نتكرافت
سوفوس
VIPRE
Webroot

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of 5ww-umb.com · checked Jul 31, 2026

100
Good
Performance
FCP
0.76s
First Contentful Paint
LCP
1.05s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
0.83s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Stored Capture Evidence1 snapshot

Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.

Archived HTTP response HTTP 200
Requested URL: http://5ww-umb.com/
UMB Direct Login
الاستجابة
HTTP 200
HTML body
15.2 KB
Compressed
3.2 KB
Links
20 internal · 0 external
Detected technologies
nginx
Selected response headers
Server: nginx/1.30.2
Content-Type: text/html; charset=UTF-8
Content-Encoding: gzip
HSTS: not observed DNSSEC: not observed WAF / firewall: not observed Cloaking flag: not observed
Favicon fingerprint: 60562060153d10d3b70909724b985ed670685e8d6aedb683804809d14ee9d001
All stored response-header names (7)
ServerDateContent-TypeContent-LengthConnectionVaryContent-Encoding

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

ScamAdviserScamAdviser درجة الثقة 80/100الحالة: Likely Safeفتح المصدر
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/5ww-umb.com"
  title="PhishDestroy threat report for 5ww-umb.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.