الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 10. قوائم الحظر العامة التي تبلغ عن تطابق: 1. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

bafybeidgsjkjmydcyqrmho4tx2fp7rf346ii4hkxr7ct2clew6d6iymuku[.]ipfs[.]dweb[.]link

“Road to TGE | MegaETH”

حكم التهديد حرجة 85/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 10/91 تطابقات القائمة السوداء المخزنة: 1 URLQuery threat systems: 1 alert نوع الاحتيال: Brand Impersonation
30/04/2026 CDN
ملخص التقرير

bafybeidgsjkjmydcyqrmho4tx2fp7rf346ii4hkxr7ct2clew6d6iymuku.ipfs.dweb.link — المحتوى غير متوفر. نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 10/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 1 alert; 1 external blocklist match (ScamSniffer); PhishDestroy score 85/100. مسجّل النطاق: CSC.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
E62E5583
الدرجة
85/100

This domain, hosted on the InterPlanetary File System (IPFS) gateway dweb.link, impersonates MegaETH under the pretext of a "Road to TGE" (Token Generation Event) campaign. The site is designed to deploy crypto drainer malware, a type of malicious software that automatically siphons cryptocurrency from connected wallets without user consent. Victims are typically lured through social engineering tactics, such as fake airdrop announcements or exclusive token sale offers, and prompted to connect their wallets to the fraudulent site. Once connected, the drainer executes unauthorized transactions, transferring assets to attacker-controlled wallets. This threat specifically targets users anticipating MegaETH’s token launch, exploiting the brand’s credibility and the high interest in early investment opportunities. Analysis indicates this infrastructure is highly suspicious and likely malicious. The domain, registered through CSC Corporate Domains, Inc., was created on April 30, 2026, an anomalous future date that suggests domain spoofing or a placeholder entry in registration records. At the time of detection, the domain resolved to the IP address 209.94.90.3 and used a Let’s Encrypt SSL certificate, a common tactic to appear legitimate. Security vendors on VirusTotal flagged the domain as malicious, with 16 out of 95 engines detecting it as a threat. Additionally, the domain appears on two security blocklists, including PhishDestroy and ScamSniffer, and has been assigned a trust score of 0/100 by Gridinsoft. Technical indicators reveal the use of Cloudflare and HTTP/3, which may be employed to obfuscate the true origin of the attack and evade detection. Users who visited this domain or connected a wallet to it should assume their cryptocurrency assets are at risk. Immediate action is required: disconnect the wallet from all dApps, revoke any suspicious smart contract approvals, and transfer remaining funds to a new, secure wallet. Monitor transaction history for unauthorized transfers and report any losses to the relevant blockchain explorer or wallet provider. To prevent future exposure, enable transaction simulation tools that preview wallet interactions before execution. Avoid engaging with unsolicited token sale or airdrop promotions, particularly those hosted on decentralized storage networks like IPFS, which lack centralized oversight and are frequently abused for phishing. Verify all communications through official MegaETH channels, and treat any domain claiming affiliation with an upcoming token launch as suspicious unless explicitly confirmed by the project’s verified sources.

VirusTotal
VirusTotal
10 det.
URLQuery
URLQuery
1 threat alert
شهادة TLS
Let's Encrypt
Hosting
IPFS Gateway
العمر
4 mo
الحالة المرصودة
المحتوى غير متوفر
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 10 / 91 URLQuery 1 threat-system alert PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict التقييم غير متاح حجب عناوين DNS 14 تم الفحص — لا يوجد حظر TLS valid certificate, 56d WHOIS 4 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU bafybeidgsjkjmydcyqrmho4tx2fp7rf346ii4hkxr7ct2clew6d6iymuku.ipfs.dweb.link malicious Sinkholed
Free Hosting Detected IPFS Gateway
This domain is hosted on IPFS Gateway (decentralized hosting (ipfs)). Decentralized hosting makes content removal extremely difficult, making it a preferred infrastructure for phishing and scam operat

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
14/15

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
الخادم / ASN cloudflare · AS40680 Protocol Labs
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مزود المنصة CSC US(US)
جهة الإبلاغ عن إساءة الاستخدامtldsupport@cscinfo.com, abuse@ipfs.io
عنوان IP 209.94.90.3 CDN
الموقع الجغرافيUS San Francisco, US
الشبكةAS40680 · Protocol Labs
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
الوقت حتى أول تعذّر للوصول 4 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف30/04/2026
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://bafybeidgsjkjmydcyqrmho4tx2fp7rf346ii4hkxr7ct2clew6d6iymuku.ipfs.dweb.link/
خوادم الأسماءtate.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 25/03/2026scanned 30/04/2026
TLS SAN Domainsdweb.link
Favicon Hash
عنوان الصفحة
Road to TGE | MegaETH
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 56 days
التقنيات · 3 identified
IPFS
Network storage

IPFS is a peer-to-peer hypermedia protocol that provides a distributed hypermedia web.

ipfs.tech ثقة 100٪
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com ثقة 100٪
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org ثقة 100٪
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

10 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
BitDefender
CRDF
CyRadar
Fortinet
G-Data
كاسبرسكي
LevelBlue
سوفوس
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of bafybeidgsjkjmydcyqrmho4tx2fp7rf346ii4hkxr7ct2clew6d6iymuku.ipfs.dweb.link · checked Jun 26, 2026

100
Good
Performance
FCP
0.76s
First Contentful Paint
LCP
0.76s
Largest Contentful Paint
CLS
0.001
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
0.76s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
تحليل إعدادات الموقع
Stored observations are retained with their original collection time.
security.txt Present · HTTP 200
Contact: mailto:security@ipfs.io
Expires: 2027-02-01T12:00:00Z
Languages: en

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/bafybeidgsjkjmydcyqrmho4tx2fp7rf346ii4hkxr7ct2clew6d6iymuku.ipfs.dweb.link"
  title="PhishDestroy threat report for bafybeidgsjkjmydcyqrmho4tx2fp7rf346ii4hkxr7ct2clew6d6iymuku.ipfs.dweb.link"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>