الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 13. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

change26[.]dothome[.]co[.]kr

“닷홈 | 접속이 제한된 페이지입니다.”

حكم التهديد حرجة 89/100 درجة الأدلة
التوفر لم يتم التحقق منها لم يتم التحقق من إمكانية الوصول الحالية
اكتشافات VirusTotal: 13/91 انتحال العلامة التجارية: Naver
15/06/2026 Naver

ملخص الأدلة

حرج
Evidence score
89/100

This domain, change26.dothome.co.kr, is flagged as a generic phishing site designed to harvest user credentials through fake login portals. Analysis indicates no specific brand impersonation or cryptocurrency drainer kit association, but the infrastructure aligns with credential theft campaigns. The domain mimics legitimate authentication pages to deceive users into submitting sensitive information, such as usernames, passwords, or multi-factor authentication codes, which are then exfiltrated to attacker-controlled servers. Infrastructure analysis reveals the following technical indicators: the domain was created on June 12, 2026, and registered through Inames Co., Ltd. It resolves to the IP address 112.175.185.131 and is hosted on an Apache HTTP Server. The domain appears on one security blocklist and is flagged by 13 out of 95 security vendors on VirusTotal. The SSL certificate is issued by GlobalSign nv-sa, which, while legitimate, does not mitigate the malicious intent of the domain. No Google Safe Browsing (GSB) entries were identified at the time of analysis, but the domain was proactively blocked by at least one security entity. The domain is currently offline, reducing immediate risk to users. However, historical activity suggests potential for re-emergence under a similar or altered infrastructure. Organizations are advised to monitor for related indicators, including the IP address 112.175.185.131 and registrar details, to preemptively block or investigate further connections. Users should verify domain authenticity before entering credentials, particularly on pages mimicking login portals, and report suspicious activity to their security teams for further analysis.

VirusTotal
VirusTotal
13 det.
DNS Security
2/13
رادار CF
ضار
شهادة TLS
GlobalSign nv-sa
العمر
2 mo New
الحالة المرصودة
لم يتم التحقق منها
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 13 / 91 URLQuery لم يتم التحقق منها PhishStats لم يتم التحقق منها OTX no community references رادار CF provider verdict: malicious URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS 2/13 TLS valid certificate, 170d WHOIS 2 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
DNS Provider Blocks 2 / 13
Controld Adblock Controld Family
CF Cloudflare Radar Verdict ضار
Phishing

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
12/14

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. VirusTotal

    6 ← 13

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: Naver report ↗
الخادم / ASN Apache · AS4766 Korea Telecom
سمعة عنوان IP IP abuse confidence 0/100 0 reports checked 12/08/2026
Registrar (base domain) Inames SE(SE)
عنوان IP 112.175.185.131 KR
الموقع الجغرافيKR Yongin-si, KR
الشبكةAS4766 · Kornet
Registration (base domain)dothome.co.kr · تم إنشاؤه 12/06/2026 (61d · New) Expires 05/03/2028
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف15/06/2026
Submitted URLhttp://change26.dothome.co.kr/user2/confirm.php
خوادم الأسماءns1.dothome.co.krns11.dothome.co.krns2.dothome.co.krns3.dothome.co.kr
بصمة TLS
رصد TLSصالح منذ 28/05/2026فُحص في 12/06/2026
الأسماء البديلة لموضوع TLSdothome.co.kr
Favicon Hash
عنوان الصفحة
닷홈 | 접속이 제한된 페이지입니다.
شهادة TLS
Valid transport encryption · صادرة عن GlobalSign nv-sa · valid for 170 days

التقنيات

حُدّدت تقنية واحدة عالية الثقة

Apache HTTP Server
Cloudflare Radar
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

13 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 13 detections
alphaMountain.ai
BitDefender
CRDF
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Lionic
MalwareURL
سوفوس
VIPRE
Webroot
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of change26.dothome.co.kr · checked Jun 25, 2026

56
Needs Work
Performance
FCP
6.56s
First Contentful Paint
LCP
7.77s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
10.95s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/change26.dothome.co.kr"
  title="PhishDestroy threat report for change26.dothome.co.kr"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>