الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 5. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

coinchanger[.]info

“CoinChanger #1 - Your Premier Crypto Exchange for Withdrawal & Transfer”

حكم التهديد حرجة 75/100 درجة الأدلة
التوفر لم يتم التحقق منها لم يتم التحقق من إمكانية الوصول الحالية
اكتشافات VirusTotal: 5/95 انتحال العلامة التجارية: Binance
21/10/2025 Binance

ملخص الأدلة

حرج
Evidence score
75/100

Analysis of coinchanger.info as of July 24, 2026, confirms active brand impersonation targeting Binance, a major cryptocurrency exchange. The domain resolves to IP 91.222.173.30, hosted on AS43641 (SOLLUTIUM EU Sp z.o.o., Netherlands). A 301 HTTP redirect is currently in place, suggesting an attempt to forward visitors to another malicious endpoint. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the risk, as fraudulent domains frequently use valid certificates to appear legitimate. Infrastructure analysis reveals the domain is registered through Vsys_USA (ASN: 43641), a registrar previously associated with phishing activity.

Nameservers ns1-us.v-sys.org and ns2-us.v-sys.org further link the domain to this provider. The page title, 'CoinChanger #1 - Your Premier Crypto Exchange for Withdrawal & Transfer,' explicitly mimics cryptocurrency exchange terminology, reinforcing the brand impersonation classification. Detection data shows 5 of 95 security vendors on VirusTotal flag the domain, while PhishDestroy and one additional blocklist have already listed it. Trust scores from Scamadviser and Gridinsoft both rate the domain at 1/100, indicating high confidence in its malicious nature.

Defenders should prioritize blocking this domain at the DNS and network levels, particularly in environments handling cryptocurrency transactions. The combination of brand impersonation, low trust scores, and active blocklist presence provides sufficient evidence for immediate action. While the exact content of the phishing pages remains unanalyzed, the infrastructure and detection patterns align with known Binance-themed scams. Further investigation into the redirect target and any associated wallet addresses is recommended to disrupt the broader campaign.

VirusTotal
VirusTotal
5 det.
شهادة TLS
Google Trust Services / WE1
الحالة المرصودة
لم يتم التحقق منها
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 5 / 95 URLQuery تم تخزين التقرير - الحكم التفصيلي معلق PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 56d WHOIS not parsed لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
مؤشرات الأمان
SA Scamadviser Warnings
This website does not have many visitors We found many low rated websites on the same server We detected cryptocurrency services which can be high risk We found several negative reviews about this site It appears that this website trades NFTs
This website offers payment methods which allow you to get your money back According to the SSL check the certificate is valid DNSFilter considers this website safe
GS Gridinsoft Analysis
Hosting SSL Certificate Cryptocurrency Reliable Payment Method Cryptocurrency - Risk Payoneer Trustpilot Rating Bootstrap Framework

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
10/12

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. حالة النطاق

    يمكن الوصول إليه ← يتعذر الوصول إليه

  2. Cloudflare Radar

    تم حفظ فحص Cloudflare Radar · فتح الفحص

  3. حالة النطاق

    يتعذر الوصول إليه ← يمكن الوصول إليه

لقطة محفوظة

عنوان الصفحة
CoinChanger #1 - Your Premier Crypto Exchange for Withdrawal & Transfer
Impersonates
Binance Ethereum Google PayPal Solana Tron Trust Wallet Wise
شهادة TLS
Valid transport encryption · صادرة عن Google Trust Services / WE1 · valid for 56 days

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN nginx · AS43641 Sollutium-NL SOLLUTIUM EU Sp z.o.o., PL
سمعة عنوان IP IP abuse confidence 0/100 0 reports checked 19/07/2026
مسجّل النطاق Vsys_USA (ASN: 43641)
عنوان IP 91.222.173.30 NL
الموقع الجغرافيNL Haarlem, NL
الشبكةAS43641 · SOLLUTIUM EU Sp z.o.o.
Elapsed Since First Report 190 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: لم يتم التحقق منها.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف21/10/2025
DOM Analysisanalyzed 23/04/2026DOM analysis score 25/1008 brand signals
Submitted URLhttps://coinchanger.info/
خوادم الأسماءns1-us.v-sys.orgns2-us.v-sys.org
بصمة TLS
رصد TLSصالح منذ 10/07/2026فُحص في 19/07/2026
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

5 / قام موردو الأمان 95 بوضع علامة على هذا المجال
View on VT
Last analyzed
alphaMountain.ai
CyRadar
Fortinet
Seclookup
Webroot

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

GridinsoftGridinsoft درجة الثقة 1/100الحالة: Suspiciousفتح المصدر
ScamAdviserScamAdviser درجة الثقة 1/100الحالة: Very Likely Unsafeفتح المصدر
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/coinchanger.info"
  title="PhishDestroy threat report for coinchanger.info"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.