الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref 5225B26D

MALICIOUS — CRITICAL

فحص التصيد والأمان للنطاق clonmove.vercel.app

clonmove[.]vercel[.]app

The domain clonmove.vercel.app is assessed as a high-risk domain specifically for credential theft.

100/100 evidence score · Critical
VirusTotal
22/91
Blocklists
No stored match
التوفر
المحتوى غير متوفر · HTTP 451
Report / Add Evidence Appeal this listing
2026-06-27 08:14 UTCالمحتوى غير متوفر · HTTP 451

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 22. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
Jump to section
ملخص التقرير

clonmove.vercel.app — المحتوى غير متوفر (HTTP 451). انتحال العلامة التجارية: Netflix; نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 22/91 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 3 alerts; URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. مسجّل النطاق: Vercel.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref 5225B26D

The domain clonmove.vercel.app is assessed as a high-risk domain specifically for credential theft. This assessment is based on the domain's technical indicators and the threat it poses to users who may inadvertently interact with it.

Analysis indicates that clonmove.vercel.app is flagged by 21 out of 95 security vendors on VirusTotal, suggesting a significant level of detection by cybersecurity tools. The domain is registered through Vercel Inc., a popular cloud-based web development platform, which may lend an air of legitimacy to unsuspecting users. It resolves to the IP address 216.198.79.3, and the SSL certificate is issued by Google Trust Services, further complicating detection efforts. The domain has been flagged by Google Safe Browsing for SOCIAL_ENGINEERING, indicating that it is being used to trick users into providing sensitive information. As of the current status, the domain remains active, posing a continuous threat to potential victims.

To mitigate the risk of credential theft associated with clonmove.vercel.app, organizations and individuals should implement several security measures. These include user education on the signs of phishing attacks, such as unexpected emails or messages that request login credentials. Network administrators should consider blocking the domain and its associated IP address to prevent access from within the network. Additionally, using multi-factor authentication (MFA) can significantly reduce the impact of stolen credentials. Regularly updating and patching systems to protect against vulnerabilities that could be exploited by attackers is also crucial. Security teams should monitor for any suspicious activity related to this domain and report it to the appropriate authorities or incident response teams.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
22 det.
URLQuery
URLQuery
3 threat alerts
رادار CF
ضار
شهادة TLS
Google Trust Services
العمر
2 mo New
الحالة المرصودة
المحتوى غير متوفر 451
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات12 recorded checks
VirusTotal 22 / 91 URLQuery 3 threat-system alerts PhishStats لم يتم التحقق منها OTX no community references رادار CF provider verdict: malicious URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 30d WHOIS 2 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
Cloudflare DNS clonmove.vercel.app malicious Sinkholed
OpenDNS clonmove.vercel.app phishing Phishing Block
DNS4EU clonmove.vercel.app malicious Sinkholed
CF Cloudflare Radar Verdict ضار
Phishing

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
13/14
تم استيعاب التهديد
clonmove.vercel.app تم اكتشافها وإدراجها في قائمة الانتظار لإجراء تحليل شامل
26/06/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
27/06/2026
URLScan Verdict
URLScan returned a malicious verdict · score 100
29/07/2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
22/91 recorded on VirusTotal
27/06/2026
Google Safe Browsing
26/06/2026
CF Radar: Malicious
Cloudflare Radar classified this domain as phishing
Brand Impersonation
Impersonation of Netflix
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
27/06/2026
Technical Analysis Recorded
يحتوي التقرير على التكنولوجيا المخزنة أو نتائج تحليل الطب الشرعي.
09/08/2026
Complaint Draft Available
لا يتم تسجيل أي تقديم. يمكنك إنشاء مسودة ومراجعتها وتقديمها بنفسك إلى السلطة المختصة.
تم نشر قائمة «DestroyList»
26/06/2026
Content Observed Unavailable
تشير أحدث عمليات التحقق المخزنة إلى أن المحتوى الذي تم الإبلاغ عنه غير متوفر؛ هذا لا يحدد من أو ما سبب التغيير.
25/07/2026
الوقت حتى أول تعذّر للوصول
انقضت ساعات 541 منذ الكشف وحتى أول ملاحظة غير متاحة.

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: Netflix report ↗
Google Safe Browsing تم وضع علامة عليها Social engineering checked 26/06/2026
الخادم / ASN Vercel · AS16509 AMAZON-02 - Amazon.com, Inc., US
IP Context Vercel shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مزود المنصة Vercel US(US)
جهة الإبلاغ عن إساءة الاستخدامabuse@vercel.com
عنوان IP 216.198.79.67 CDN
الموقع الجغرافيUS Walnut, US
الشبكةAS16509 · Amazon.com, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
حالة HTTP451 Unavailable For Legal Reasons
الوقت حتى أول تعذّر للوصول 23 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف26/06/2026
DOM Analysisanalyzed 26/06/2026score 100/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://clonmove.vercel.app/login
TLS Fingerprint
TLS Observationvalid from 28/04/2026scanned 26/06/2026
TLS SAN Domainsvercel.app
عنوان الصفحة
Netflix
شهادة TLS
Valid transport encryption · صادرة عن Google Trust Services · valid for 30 days
التقنيات · 2 identified
Vercel
PaaS

Vercel is a cloud platform for static frontends and serverless functions.

vercel.com ثقة 100٪
HSTS
الأمن

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org ثقة 100٪
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

22 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed
Criminal IP
alphaMountain.ai
BitDefender
CyRadar
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Google Safebrowsing
Gridinsoft
كاسبرسكي
LevelBlue
Lionic
MalwareURL
نتكرافت
OpenPhish
SafeToOpen
سوفوس
URLQuery
VIPRE
Webroot
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of clonmove.vercel.app · checked Jun 26, 2026

72
Needs Work
Performance
FCP
2.71s
First Contentful Paint
LCP
2.73s
Largest Contentful Paint
CLS
0.436
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
2.71s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/clonmove.vercel.app"
  title="PhishDestroy threat report for clonmove.vercel.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>