aiysha[.]jp
“403 Forbidden”
ملخص الأدلة
Domain aiysha.jp is currently hosting a generic phishing campaign identified as a crypto drainer designed to steal cryptocurrency funds through fake login pages. No specific brand impersonation has been confirmed at this stage, but the campaign follows typical drainer kit behavior, including obfuscated JavaScript payloads and automated fund transfer mechanisms. The domain leverages social engineering to trick users into connecting their wallets or entering credentials, which are then exfiltrated to attacker-controlled addresses. This domain was registered on March 17, 2016, and is currently resolving to IP address 112.78.112.34. According to VirusTotal analysis dated from seed 4a76d7, the domain has 0 detections out of 95 scans, indicating it remains under the radar of most security vendors. The domain uses a valid SSL certificate issued by Let's Encrypt, likely to enhance credibility and bypass browser security warnings. As of the latest scan, no blocklist entries were recorded, and Google Safe Browsing (GSB) status remains unflagged. The registrar is not specified in the available data, but the domain's age and low detection rate suggest a deliberate strategy to avoid early detection. The campaign is classified as active and under investigation, with a current risk level of under_investigation. PhishDestroy has flagged this domain via seed 4a76d7 and is actively monitoring for infrastructure changes or expanded targeting. Immediate action is recommended: users are advised to avoid interacting with aiysha.jp and to verify any suspicious links using PhishDestroy's real-time scanning tool. While no confirmed incidents of fund loss have been reported yet, the combination of low detection, valid SSL, and drainer-style behavior indicates a significant risk of fraudulent activity. Remain vigilant and report any wallet connections or login prompts originating from this domain.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
التقنيات
حُدّدَت تقنيتان عاليتا الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب