الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 16. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

97bal[.]luxente[.]cc

“403 Forbidden”

حكم التهديد حرجة 95/100 درجة الأدلة
التوفر خطأ في الخادم آخر استجابة مخزنة كانت غير حاسمة
اكتشافات VirusTotal: 16/93 URLQuery threat systems: 4 alerts
25/02/2026 1 Report Sent
ملخص التقرير

97bal.luxente.cc — خطأ في الخادم (HTTP 502). ملخص الأدلة: VirusTotal 16/93 (alphaMountain.ai, CRDF, DNS8, Emsisoft, Forcepoint ThreatSeeker); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: NiceNIC.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
96AF4AC1
الدرجة
95/100

The domain 97bal.luxente.cc was registered on February 25, 2026 through NiceNIC International Group Co., Limited and is currently listed as offline. DNS resolution points to the IPv4 address 217.60.62.75, which belongs to AS56971 Cloud in Finland. The authoritative nameservers are a.dnspod.com and c.dnspod.com, both typical of the DNSPod service. An HTTPS endpoint is secured with a Let’s Encrypt certificate (R13), indicating that the operator obtained a free TLS certificate to lend legitimacy to the site.

When accessed, the web server returns a 403 Forbidden page title, providing no further content for analysis. VirusTotal records indicate that 16 out of 93 scanning engines flag the domain, suggesting a moderate level of detection across anti‑malware products. Reputation services show a Scamadviser trust score of 41 / 100 and a Gridinsoft score of 0 / 100, reinforcing the assessment that the site is untrustworthy. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy mitigation platform.

No additional intelligence such as target brand, phishing kit, or payload details is available, and the exact nature of the phishing campaign remains opaque. Defenders should continue to block the domain and its resolved IP address at network perimeter controls, update local blocklists, and monitor for any re‑hosting attempts under related subdomains or similar naming patterns. Given the limited public evidence, ongoing telemetry collection from DNS queries, TLS handshakes, and any future HTTP responses is recommended to refine the threat profile and to detect possible resurgence of the infrastructure.

VirusTotal
VirusTotal
16 det.
URLQuery
URLQuery
4 threat alerts
رادار CF
ضار
ScamAdviser
Scamadviser
41/100
شهادة TLS
R13
العمر
6 mo
الحالة المرصودة
خطأ في الخادم 502
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات VirusTotal 16 / 93 URLQuery 4 threat-system alerts PhishStats لم يتم التحقق منها OTX no community references رادار CF provider verdict: malicious URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 85d WHOIS 6 mo old لقطة شاشة 4 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها Scamadviser 41/100
مؤشرات الأمان
SA Scamadviser Warnings 41/100
The website's owner is hiding his identity on WHOIS using a paid service This website does not have many visitors This website is being iframed by another website Several spammers and scammers use the same registrar This website has only been registered recently.
According to the SSL check the certificate is valid DNSFilter considers this website safe
استخبارات أمن الشبكات Registrar context
Threat Detection Systems 4 alerts
Detection System Indicator Verdict Alert
Quad9 DNS 97bal.luxente.cc malicious Sinkholed
OpenDNS 97bal.luxente.cc phishing Phishing Block
Hagezi Threat Feed 97bal.luxente.cc malicious Sinkholed
DNS4EU 97bal.luxente.cc malicious Sinkholed
CF Cloudflare Radar Verdict ضار
Phishing
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
16/17
Sent Report Recorded
Stored sent-report record for registrar NiceNIC International Group Co., Limited, hosting provider, 3 abuse contacts
abuse@nicenic.netabuse@verisign-grs.comcompliance@icann.org
25/02/2026

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN nginx · AS56971 AS56971 Cloud
سمعة عنوان IP abuse score 0/100 0 reports checked 10/08/2026
Registrar (base domain) NiceNIC RU(RU) PhishDestroy Investigation
جهة الإبلاغ عن إساءة الاستخدامabuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org
البحث في قاعدة بيانات WHOISICANN RDAP لـ luxente.cc →
عنوان IP 217.60.62.75 FI
الموقع الجغرافيFI Helsinki, FI
الشبكةAS56971 · AS56971 Cloud
Registration (base domain)luxente.cc · تم إنشاؤه 25/02/2026 (170d) Expires 23/02/2027
حالة HTTP502 Error
Elapsed Since First Report 76 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: خطأ في الخادم.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف25/02/2026
DOM Analysisanalyzed 23/04/2026score 0/100
IoC Extractionscanned 02/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://97bal.luxente.cc/
خوادم الأسماءc.dnspod.com
TLS Observationvalid from 28/02/2026scanned 15/03/2026
Case ID
عنوان الصفحة
403 Forbidden
شهادة TLS
Valid transport encryption · صادرة عن R13 · valid for 85 days

Latest Classified Outcome 2026-08-14 03:13:33 UTC

Primary outcome Registration hold observed reason: Registrar clientHold 95% confidence
Attribution NICENIC INTERNATIONAL GROUP CO., LIMITED mechanism: Registrar clientHold source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Registrar clientHold
Latest HTTP observation غير معروف Origin unreachable Http 5xx 20% 2026-08-14 02:30:45 UTC
RDAP registration Registrar clientHold NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientHoldclientTransferProhibited expires 2027-02-23 08:00:35 UTC checked 2026-08-14 03:13:33 UTC
Registrar action marker verified clientHold marker NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 causal link to our report not established
Observed timeline last reachable: 2026-06-14 22:39:56 UTC current episode first observed: 2026-08-05 01:45:38 UTC observed RIP window: 2026-06-14 22:39:56 UTC → 2026-08-05 01:45:38 UTC · 1,227.10h midpoint estimate ≈ 2026-07-10 12:12:47 UTC · precision very low · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

16 / قام موردو الأمان 93 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 9 detections
alphaMountain.ai
CRDF
DNS8
Emsisoft
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
نتكرافت
Webroot

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive

الأدلة والتقارير الخارجية

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260225-814472 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org
Page title stored with report: 403 Forbidden
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 3.2 KB
نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/97bal.luxente.cc"
  title="PhishDestroy threat report for 97bal.luxente.cc"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>