الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 5. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

648aa6b9e132c[.]site123[.]me

“financial-journey - Metamask Extension”

حكم التهديد عالية 65/100 درجة الأدلة
التوفر لم يتم التحقق منها لم يتم التحقق من إمكانية الوصول الحالية
اكتشافات VirusTotal: 5/91 انتحال العلامة التجارية: MetaMask
25/12/2025 MetaMask
ملخص التقرير

648aa6b9e132c.site123.me — لم يتم التحقق منها. انتحال العلامة التجارية: MetaMask; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 5/91 (ChainPatrol, alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Gridinsoft); PhishDestroy score 65/100. مسجّل النطاق: GoDaddy.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
مرتفع
المرجع
33E69441
الدرجة
65/100

On July 24, 2026, the domain 648aa6b9e132c.site123.me was examined after being reported by PhishDestroy. The domain was created on December 3, 2015 and is registered through GoDaddy.com, LLC. DNS resolution points to the IPv4 address 185.111.111.158, which belongs to ASN AS212238 operated by Datacamp Limited and is geolocated in Germany. The site presents an SSL certificate issued by ZeroSSL under the ZeroSSL RSA Domain Secure Site CA, indicating that TLS is available but does not provide any insight into the content. HTTP requests return a 202 status code, an atypical response for a static page, and the only detected technology is listed as “Bunny”. The page title returned from the server is “financial-journey - Metamask Extension”, directly referencing the MetaMask brand and suggesting a crypto‑related scam.

The infrastructure is classified as a crypto scam that impersonates MetaMask, matching the known brand target. VirusTotal analysis shows that five of ninety‑three scanning engines flagged the domain, and the domain appears on a single external blocklist. PhishDestroy has already blocked the domain, and the Gridinsoft trust score is 0 out of 100, reflecting a high likelihood of malicious intent. Nameserver queries returned no results (NS_NOT_FOUND), limiting further DNS‑based attribution. The current status is offline, indicating that the site has been taken down or is otherwise inaccessible.

Uncertainties remain regarding the exact payload or phishing workflow because the page content has not been captured; only the title and metadata are available. Defensive recommendations include adding the IP address 185.111.111.158 to network deny lists, continuing to block the domain at perimeter and endpoint layers, monitoring for new subdomains under the same registrar or ASN, and reviewing any internal logs for attempts to access the URL or the page title.

VirusTotal
VirusTotal
5 det.
شهادة TLS
ZeroSSL / ZeroSSL RSA Domain Secure Site CA
العمر
10.7 yr
الحالة المرصودة
لم يتم التحقق منها
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 5 / 91 URLQuery تم تخزين التقرير - الحكم التفصيلي معلق PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 95d WHOIS 130 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
15/17

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN BunnyCDN-DE1-1332 · AS212238 CDNEXT Datacamp Limited, GB
سمعة عنوان IP abuse score 41/100 30 reports checked 28/07/2026
Registrar (base domain) GoDaddy US(US)
جهة الإبلاغ عن إساءة الاستخدامabuse@datacamp.co.uk
البحث في قاعدة بيانات WHOISICANN RDAP لـ site123.me →
عنوان IP 185.111.111.158 DE
الموقع الجغرافيDE Frankfurt am Main, DE
الشبكةAS212238 · Datacamp Limited
Registration (base domain)site123.me · تم إنشاؤه 03/12/2015
Elapsed Since First Report 80 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: لم يتم التحقق منها.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف25/12/2025
DOM Analysisanalyzed 11/03/2026score 10/1004 brand signals
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://648aa6b9e132c.site123.me/
TLS Fingerprint
TLS Observationvalid from 23/11/2025scanned 12/03/2026
TLS SAN Domainssite123.me
Favicon Hash
عنوان الصفحة
financial-journey - Metamask Extension
Impersonates
Binance Ethereum MetaMask Trezor
شهادة TLS
Valid transport encryption · صادرة عن ZeroSSL / ZeroSSL RSA Domain Secure Site CA · valid for 95 days
التقنيات · 1 identified
Bunny
CDN

Content Delivery Network — caches assets at edge locations for faster global delivery.

bunny.net ثقة 100٪
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

5 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 5 detections
ChainPatrol
alphaMountain.ai
Chong Lua Dao
Forcepoint ThreatSeeker
Gridinsoft

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of 648aa6b9e132c.site123.me · checked Mar 2, 2026

56
Needs Work
Performance
FCP
5.11s
First Contentful Paint
LCP
7.8s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
327ms
Total Blocking Time
SI
5.11s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
تحليل إعدادات الموقع
Stored observations are retained with their original collection time.

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/648aa6b9e132c.site123.me"
  title="PhishDestroy threat report for 648aa6b9e132c.site123.me"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>