الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 1. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

baxus[.]co

فحص التصيد والأمان للنطاق baxus.co

“BAXUS”

حكم التهديد عالية 65/100 درجة الأدلة
التوفر آخر نشاط معروف أحدث مراقبة إمكانية الوصول المخزنة
إشارات الخطر
اكتشافات VirusTotal: 1/91 انتحال العلامة التجارية: Jito آخر نشاط معروف
1/91 VT 04/11/2025 Jito Brand Impersonation US US
ملخص التقرير

baxus.co — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Jito; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 1/91 (SOCRadar); PhishDestroy score 65/100. مسجّل النطاق: Key-Systems.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
مرتفع
المرجع
55211BE5
الدرجة
65/100

The domain baxus.co is a confirmed phishing site engaged in brand impersonation targeting the jito platform. It presents itself as a legitimate service to deceive users into disclosing sensitive information or interacting with fraudulent interfaces, though no crypto drainer kit has been identified. As of the latest verification, baxus.co has been taken offline, reducing immediate risk to potential victims.

Technical analysis shows baxus.co registered through Key-Systems GmbH on May 09, 2021, resolving to the IP address 34.110.186.216, hosted on Google Cloud infrastructure (AS396982). Security scans reveal 0 of 95 VirusTotal vendors flagged the domain, and Google Safe Browsing does not list it as malicious. However, it appears on 1 security blocklist (PhishDestroy). The SSL certificate is issued by Google Trust Services / WR3, and observed technologies include Google Maps, Cloudflare, Amazon Web Services, and Sendgrid. The page title displayed was 'BAXUS'.

Users who interacted with baxus.co should immediately change any credentials entered on the site and enable two-factor authentication on their accounts. Monitor financial and login activity for signs of fraud. If crypto assets were involved, revoke any token approvals granted to the domain and consider transferring funds to a new wallet. Report the phishing domain to the impersonated brand (jito) and submit it to platforms like PhishTank, Google Safe Browsing, or local cybersecurity authorities for further investigation.

VirusTotal
VirusTotal
1 det.
Gridinsoft
75/100
ScamAdviser
Scamadviser
71/100
شهادة TLS
منتهية الصلاحية أو غير متحقق منها -94d
العمر
5.3 yr
الحالة المرصودة
آخر نشاط معروف 200
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 1 / 91 URLQuery تم تخزين التقرير - الحكم التفصيلي معلق PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 64 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها Gridinsoft 75/100 Scamadviser 71/100
مؤشرات الأمان
SA Scamadviser Warnings 71/100
The website's owner is hiding his identity on WHOIS using a paid service This website does not have many visitors We detected cryptocurrency services which can be high risk It appears that this website trades NFTs
According to the SSL check the certificate is valid This website has existed for quite some years DNSFilter considers this website safe
GS Gridinsoft Analysis 75 / 100
Hosting SSL Certificate Popular Bank Cryptocurrency NFTs Registration Form Google Tag Manager Google Maps

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
13/15

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN UploadServer · AS396982 GOOGLE-CLOUD-PLATFORM, US
سمعة عنوان IP abuse score 0/100 0 reports checked 18/07/2026
عنوان IP 34.110.186.216 US
الموقع الجغرافيUS Kansas City, US
الشبكةAS396982 · Google LLC
التسجيلتم إنشاؤه 09/05/2021 Expires 09/05/2026
Elapsed Since First Report 131 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: آخر نشاط معروف.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
حالة HTTP200
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف04/11/2025
DOM Analysisanalyzed 11/03/2026score 10/1001 brand signal
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://baxus.co/
خوادم الأسماءns-cloud-d1.googledomains.comns-cloud-d2.googledomains.comns-cloud-d3.googledomains.comns-cloud-d4.googledomains.com
TLS Fingerprint
TLS Observationvalid from 07/02/2026scanned 11/03/2026
Favicon Hash
عنوان الصفحة
BAXUS
Impersonates
Jito
شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن Google Trust Services / WR3
التقنيات · 12 identified
Google Maps
Google Cloud
PaaS IaaS

Suite of cloud computing services running on Google infrastructure.

Amazon Web Services
PaaS IaaS

Cloud computing platform offering compute, storage, and networking services.

Cloudflare
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
Sendgrid
Hotjar

User-behavior analytics: heatmaps, session recordings, on-site surveys.

Hammer.js
HSTS
الأمن

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

Google Cloud CDN
CDN

Content delivery network built on Google global edge infrastructure.

cdnjs
Amazon S3
HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

1 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
SOCRadar

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of baxus.co · checked Mar 7, 2026

54
Needs Work
Performance
FCP
3.06s
First Contentful Paint
LCP
15.9s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
298ms
Total Blocking Time
SI
10.36s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
تحليل إعدادات الموقع
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
Sitemap 288 pages · HTTP 200

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/baxus.co"
  title="PhishDestroy threat report for baxus.co"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>