الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 15. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@hkdns.hk. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
5 months
Reports sent
1
Latest case ID
PD-20260313-CE1173
Current status
Observed active at latest stored check
أمن المجال وذكاء التهديدات

cabbage[.]cyclamen-zjk[.]comwww[.]hzboligang[.]com

“Home”

حكم التهديد حرجة 95/100 درجة الأدلة
التوفر مغطى بعباءة · يمكن الوصول إليه تمت ملاحظة إمكانية الوصول من خلال عمليات فحص إخفاء الهوية
اكتشافات VirusTotal: 15/91 انتحال العلامة التجارية: Apple آخر نشاط معروف
13/03/2026 Apple 1 Report Sent
ملخص التقرير

cabbage.cyclamen-zjk.comwww.hzboligang.com — مغطى بعباءة · يمكن الوصول إليه. انتحال العلامة التجارية: Apple; نوع الاحتيال: Tech Support Scam. ملخص الأدلة: VirusTotal 15/91 (ADMINUSLabs, BitDefender, Chong Lua Dao, CRDF, CyRadar); cloaking observed; PhishDestroy score 95/100. مسجّل النطاق: West263 International.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
16766E0C
الدرجة
95/100

The domain cabbage.cyclamen-zjk.comwww.hzboligang.com is currently classified as a high‑risk Apple brand‑impersonation site. It was registered on 13 March 2026 through West263 International Limited and remains active as of 12 July 2026. The site presents a generic “Home” page and serves content over HTTPS using a Let’s Encrypt R13 certificate, indicating that encryption is deliberately provided to increase credibility.

Network analysis shows the domain resolves to the IPv4 address 172.247.146.162, which belongs to AS40065 (CNSERVERS LLC) located in the United States. Authoritative name servers are ns1.myhostadmin.net, ns2.myhostadmin.net, ns3.myhostadmin.net, and ns4.myhostadmin.net. The web server reports HTTP 200 and employs Nginx with HSTS and HTTP/3 enabled, while the front‑end stack includes Bootstrap, jQuery, and the Slick carousel library.

Reputation services assign a Gridinsoft trust score of 0 / 100, and VirusTotal records only two of ninety‑five scanners flagging the domain as malicious. The site is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy service. The low number of detections suggests limited visibility in the broader security community, leaving uncertainty about the full extent of the campaign’s infrastructure and any additional payloads that may be delivered.

Defenders should add the full host name to DNS filtering rules and block outbound connections to 172.247.146.162. Network‑level detection can be reinforced by monitoring TLS handshakes for the Let’s Encrypt R13 certificate and by flagging HTTP/3 traffic to the identified name servers. Incident response teams are advised to educate users about unsolicited Apple‑related support prompts, as the site appears to employ a tech‑support scam narrative. Continuous re‑evaluation of VirusTotal and other sandbox results is recommended to capture any future changes in malicious behavior.

VirusTotal
VirusTotal
15 det.
شهادة TLS
Let's Encrypt
العمر
5 mo
الحالة المرصودة
مغطى بعباءة · يمكن الوصول إليه
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات VirusTotal 15 / 91 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 14 تم الفحص — لا يوجد حظر TLS valid certificate, 49d WHOIS 5 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
12/13
Sent Report Recorded
Stored sent-report record for registrar West263 International Limited, hosting provider, 2 abuse contacts
abuse@hkdns.hkabuse@ceranetworks.com
13/03/2026

حالة قوائم الحظر العامة

لقطة محفوظة

عنوان الصفحة
الصفحة الرئيسية
Impersonates
Apple Aptos Cosmos Google Polygon Solana Tron
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 49 days

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN nginx · AS40065 CNSERVERS LLC
سمعة عنوان IP abuse score 0/100 0 reports checked 13/08/2026
Registrar (base domain) West263 International HK(HK)
جهة الإبلاغ عن إساءة الاستخدامabuse@hkdns.hk, abuse@ceranetworks.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ hzboligang.com →
عنوان IP 172.247.146.162 US
الموقع الجغرافيUS Los Angeles, US
الشبكةAS40065 · CNSERVERS LLC
Registration (base domain)hzboligang.com · تم إنشاؤه 13/03/2026 (160d)
Cloaking Cloaking Detected Content divergence · score 4/6
unavailable: raw=proxy_error; http=0; via=http_proxy; error=HTTPConnectionPool(host='82.29.229.214', port=6569): Max retries exceeded with url: http://cabbage.cyclamen-zjk.comwww.h
checked 21/08/2026
Elapsed Since First Report 46 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: مغطى بعباءة · يمكن الوصول إليه.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف13/03/2026
DOM Analysisanalyzed 24/03/2026score 86/1007 brand signals
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://cabbage.cyclamen-zjk.comwww.hzboligang.com/
خوادم الأسماءns6.myhostadmin.net
TLS Fingerprint
TLS Observationvalid from 31/01/2026scanned 15/03/2026
TLS SAN Domainsfound.eedsrcyy.comwww.hzboligang.comhzboligang.comm.hzboligang.commiu.hmyzj.comwww.hzboligang.commusic.hnzspump.comwww.hzboligang.comqi.hmyzj.comwww.hzboligang.comwww.hzboligang.com
Favicon Hash
Case ID
ICANN OVERSIGHT Registration: hzboligang.com

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain hzboligang.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.

الاستخبارات الجنائية الرقمية

Phishing Form Targets 1
/plus/search.php
التقنيات · 6 identified
Bootstrap
UI frameworks

Popular CSS framework for responsive, mobile-first web development.

Nginx
Web servers Reverse proxies

High-performance HTTP server and reverse proxy, known for stability and low resource usage.

Slick
jQuery
JavaScript libraries

Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.

HSTS
الأمن

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

15 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 2 detections
ADMINUSLabs
BitDefender
Chong Lua Dao
CRDF
CyRadar
Emsisoft
Fortinet
G-Data
Gridinsoft
LevelBlue
Lionic
نتكرافت
SOCRadar
سوفوس
Webroot
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of cabbage.cyclamen-zjk.comwww.hzboligang.com · checked Mar 13, 2026

76
Needs Work
Performance
FCP
1.35s
First Contentful Paint
LCP
5.93s
Largest Contentful Paint
CLS
0.001
Cumulative Layout Shift
TBT
27ms
Total Blocking Time
SI
3.98s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
تحليل إعدادات الموقع
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.

الأدلة والتقارير الخارجية

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260313-CE1173 Recipient: abuse@hkdns.hk
Page title stored with report: TP官方下载|TPWallet官网正版下载-tp官网最新安卓版下载app|你的通用数字钱包
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 250.4 KB
نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/cabbage.cyclamen-zjk.comwww.hzboligang.com"
  title="PhishDestroy threat report for cabbage.cyclamen-zjk.comwww.hzboligang.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.