aurumfoundation[.]app
فحص التصيد والأمان للنطاق aurumfoundation.app
“Verification Portal”
aurumfoundation.app — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Google; نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 1/91 (CRDF); URLQuery 2 alerts; 1 external blocklist match (ScamSniffer); PhishDestroy score 58/100. مسجّل النطاق: Namecheap.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
On July 27, 2026 the domain aurumfoundation.app was registered through Namecheap Inc. The domain is currently active and resolves to the IPv4 address 34.111.179.208. DNS resolution is served by dns1.registrar-servers.com and dns2.registrar-servers.com. Analysis of the hosting environment shows the site runs on Google Cloud infrastructure, employing Node.js with the Express framework, and is delivered via Google Cloud CDN with HTTP/3 support. Transport security is enforced through HTTP Strict Transport Security (HSTS).
The domain has been flagged by one of ninety‑one security vendors on VirusTotal, indicating a single detection of malicious activity. It is also listed on a security blocklist and has been actively blocked by the PhishDestroy filtering service. No additional public threat‑intel sources (e.g., OTX, Safe Browsing) are referenced in the available data, and no page‑title or brand information has been disclosed, leaving the exact phishing lure undefined. The limited detection footprint—one vendor flag and a single blocklist entry—suggests the campaign may be in an early deployment stage or using a low‑profile hosting configuration to evade broader detection.
Defenders should add aurumfoundation.app to outbound‑traffic monitoring rules, enforce DNS sinkholing where possible, and ensure that any credential‑capture attempts targeting the domain are logged and investigated. Continuous re‑scanning on multi‑vendor platforms is recommended to capture any future detections, and threat‑intel feeds should be updated to reflect the domain’s presence on blocklists. Given the active status, the combination of Node.js/Express on Google Cloud and the presence of HSTS indicates a modern web stack that may be used to host credential‑harvesting pages, reinforcing the need for vigilant network‑level controls.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org ثقة 100٪Express is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
expressjs.com ثقة 100٪HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Cloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of aurumfoundation.app · checked Aug 4, 2026
الأدلة والتقارير الخارجية
PD-20260804-58BC71 Recipient: abuse@namecheap.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب