claim[.]gweiportal[.]click
“Cryptocurrency prices, Token rates and Altcoin charts ranked by Market Capitalization and Volume | …”
claim.gweiportal.click — لم يتم التحقق منها. نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); PhishDestroy score 95/100. مسجّل النطاق: Dynadot.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain claim.gweiportal.click was registered on May 27 2026 through Dynadot, LLC. DNS resolution points to 104.21.1.175, a Cloudflare address located in Canada. The authoritative nameservers are george.ns.cloudflare.com and raina.ns.cloudflare.com, indicating the use of Cloudflare's DNS service. The site presents a valid Let’s Encrypt certificate (E8) and responds with an HTTP 301 status, redirecting visitors to a target page whose title is "Cryptocurrency prices, Token rates and Altcoin charts ranked by Market Capitalization and Volume | CryptoRank.io". The page title suggests an attempt to masquerade as a legitimate cryptocurrency market data site, consistent with the classified crypto drainer threat. Reputation scoring from Gridinsoft is 0/100, and the domain is listed on at least one public blocklist, including PhishDestroy. VirusTotal records indicate that one of 91 scanning engines has flagged the domain, though the specific detection is not disclosed. The combination of recent registration, Cloudflare front‑end, low trust score, and the presence of a redirect to a crypto‑related page aligns with known crypto‑drainer campaigns that aim to harvest wallet credentials or redirect victims to malicious payment pages. At present, no additional infrastructure such as command‑and‑control servers or payload hashes has been observed. Defenders should block DNS resolution for claim.gweiportal.click, monitor outbound connections to the associated Cloudflare IP, and consider adding the domain to internal URL filtering lists. Continuous re‑assessment is recommended as further intelligence, such as malicious payload delivery or victim reports, may emerge.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: gweiportal.click
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain gweiportal.click behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب