cnangelly[.]xyz
“Cryptocurrency Exchange - Crypto & Altcoin Swap Platform with Lowest Fees”
cnangelly.xyz — المحتوى غير متوفر. انتحال العلامة التجارية: Ebay; نوع الاحتيال: Wallet/seed Phishing. ملخص الأدلة: VirusTotal 12/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 91/100. مسجّل النطاق: Porkbun.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of cnangelly.xyz shows a brand impersonation campaign targeting eBay users with a wallet/seed phishing lure. The domain was registered on July 29, 2025 through Porkbun LLC and is served by the Porkbun nameservers curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, and salvador.ns.porkbun.com. DNS resolution points to IP address 62.60.226.213, which belongs to AS214351 FEMO IT SOLUTIONS LIMITED located in Germany. The site lacks an SSL/TLS certificate and its HTTP status is currently offline, confirming that the infrastructure has been taken down.
Reputation services flag the domain as highly untrustworthy: Gridinsoft assigns a trust score of 0 out of 100, Scamadviser rates it 1 out of 100, and it appears on one security blocklist. Malicious content detection is corroborated by VirusTotal, where 12 of 95 scanning engines flag the domain as malicious. Additionally, the domain is listed as blocked by PhishDestroy.
The page title observed during the brief live period was "Cryptocurrency Exchange - Crypto & Altcoin Swap Platform with Lowest Fees," indicating that the attacker attempts to lure victims into a crypto‑related credential harvest. Defenders should block outbound connections to 62.60.226.213, add cnangelly.xyz to URL filtering and email security policies, and monitor for any residual activity tied to the Porkbun nameservers. Continuous watch of the associated IP and registrar may reveal re‑use of the infrastructure in future campaigns.
مؤشرات الأمان
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب