chainversedrop[.]com
فحص التصيد والأمان للنطاق chainversedrop.com
“Aura Pocket - We are here to help you resolve your crypto related issues”
chainversedrop.com — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Across; نوع الاحتيال: Fake Airdrop. ملخص الأدلة: VT 9/93 (alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker, Fortinet); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 1 (ScamSniffer); PD 87/100. مسجّل النطاق: Ultahost.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy first observed chainversedrop.com on Jan 24, 2026. Positive findings were recorded by VirusTotal and ScamSniffer. Evidence score: 87/100.
VirusTotal recorded 9 detections among 93 engines: alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker, Fortinet, G-Data, Lionic, SOCRadar on Feb 25, 2026 at 01:11 UTC. The external blocklist snapshot contained 1 match (ScamSniffer) on Aug 7, 2026 at 14:20 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0) on Mar 26, 2026 at 12:34 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:12 UTC; content was unavailable. Registration records list Ultahost, Inc. as the registrar. At collection time, the domain resolved to 159.100.6.5. Collected metadata identifies Across as the apparent target. Captured page title: “Aura Pocket - We are here to help you resolve your crypto related issues”. PhishDestroy classified the observed content as Fake Airdrop. DOM analysis completed on Apr 23, 2026 at 03:22 UTC; stored DOM score 30/100. IoC extraction completed on Aug 2, 2026 at 04:16 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis24/07/2026
Analysis of chainversedrop.com shows a short‑lived infrastructure dedicated to a fake airdrop campaign. The domain was registered on February 21, 2026 through Ultahost, Inc. and uses four Ultahost nameservers (ns1‑ns4.ultahost.com). DNS resolution points to IP address 159.100.6.5, which belongs to AS214036 Ultahost, Inc. in Germany. No TLS certificate is presented, indicating the site was served over plain HTTP. The page title returned by the server reads “Aura Pocket - We are here to help you resolve your crypto related issues,” confirming the intent to lure cryptocurrency users.
VirusTotal scans flagged the domain by nine of ninety‑three security vendors, providing modest but notable detection. The domain appears on two independent blocklists—PhishDestroy and ScamSniffer—further corroborating its malicious classification. Reputation services assign extremely low scores: Scamadviser rates it 1 / 100 and Gridinsoft 0 / 100, reflecting a high likelihood of fraud. The site is currently offline, limiting direct content analysis, and no SSL certificate or additional metadata is available.
The brand target is listed as “across,” suggesting the operation may have been intended to impersonate multiple brands, but concrete brand identifiers beyond the generic crypto wording are absent. Defenders should add chainversedrop.com to URL filtering policies, block its IP address at network perimeters, and ensure DNS resolvers deny queries for the domain. Continuous monitoring of the associated IP range and the Ultahost hosting environment is advisable, as the operator may redeploy similar campaigns under new domains. Organizations should educate users about unsolicited airdrop offers and reinforce the policy of never entering private keys on unverified sites.
مؤشرات الأمان
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
حصلت ICANN على أموالها. أما المساءلة فلم تصل.
بالنسبة إلى نطاق gTLD هذا، يعمل المسجّل المذكور أعلاه بموجب عقد مع ICANN. وتحصّل ICANN رسوماً سنوية ومتغيرة ورسومًا قائمة على المعاملات مرتبطة بعمليات التسجيل والتجديد والنقل.
الاعتماد: جرت الاستفادة منه مالياً. المساءلة: يُرجى التحقق مرة أخرى لاحقاً.
ثم يبدأ السحر: تكتب ICANN البند RAA §3.18، ويتولى المسجّل التحقيق في إساءة الاستخدام داخل قاعدة عملائه، ويقدّم الضحايا الأدلة مجاناً، بينما تنتظر كل طبقة أن يتحرك طرف آخر. إذا كان ذلك يجعل الضحايا يشعرون بمزيد من الأمان، فممتاز—لقد أدّت الفاتورة مهمتها.
تحليل VirusTotal
الأدلة والتقارير الخارجية
“@cryptodrainer Telegram”
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
حول هذا التقرير: chainversedrop.com
يقدم هذا التقرير أحدث الأدلة المخزنة المتاحة لـ PhishDestroy. يتم عرض الطوابع الزمنية للمصدر حيثما كان ذلك متاحًا؛ يمكن أن تتغير أحكام التوفر والبائعين بعد التجميع.
عرض الموقع الذي تم التقاطه عنوان الصفحة “Aura Pocket - We are here to help you resolve your crypto related issues” وربما ينتحل شخصية Across.
اعتبارًا من 07/08/2026، كان لدى chainversedrop.com اكتشافات من محركات الأمان 9.
إذا كنت تعتقد أن هذه القائمة غير دقيقة، تقديم استئناف. للتعرف على منهجيتنا، قم بزيارة صفحة الأسئلة الشائعة.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب