الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 3. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

cryptorecoveryconsultant[.]com

“CRYPTO RECOVERY CONSULTANT”

حكم التهديد عالية 65/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 3/95 Spamhaus DBL: DBL_PHISH انتحال العلامة التجارية: WhatsApp
09/08/2025 WhatsApp

ملخص الأدلة

مرتفع
Evidence score
65/100

Analysis of cryptorecoveryconsultant.com indicates this domain was actively used for wallet and seed-phishing operations targeting WhatsApp users. Registered on November 9, 2024, through Atak Domain, the site resolved to IP address 198.23.141.202, hosted on AS36352 (HostPapa) in the United States. No SSL certificate was present, increasing exposure to interception. The page title, 'CRYPTO RECOVERY CONSULTANT,' suggests a focus on fraudulent cryptocurrency recovery services, a known vector for credential and seed phrase harvesting.

Security vendor assessments reflect elevated risk: Scamadviser assigned a trust score of 1/100, while Gridinsoft rated it 39/100. Three of 95 security vendors on VirusTotal flagged the domain as malicious. The domain appears on one security blocklist and is currently blocked by PhishDestroy. Nameservers ns1.sagaciousdns.com and ns2.sagaciousdns.com have been associated with other phishing infrastructure, though direct attribution to a specific threat actor or campaign remains unconfirmed.

As of July 24, 2026, the domain is offline, but its infrastructure may be reactivated or repurposed. Defenders should monitor for re-emergence on the same IP or nameserver set, particularly in campaigns targeting cryptocurrency users via messaging platforms. No evidence links this domain to broader malware distribution or exploit kit activity. The exact content and user interaction flow of the phishing page are not analysed, but the combination of low trust scores, blocklist inclusion, and absence of encryption supports classification as malicious.

VirusTotal
VirusTotal
3 det.
العمر
1.8 yr
الحالة المرصودة
المحتوى غير متوفر HTTP 502
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 3 / 95 URLQuery تم تخزين التقرير - الحكم التفصيلي معلق PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict التقييم غير متاح حجب عناوين DNS لم يتم التحقق منها TLS لا توجد بيانات للشهادة WHOIS 21 mo old لقطة شاشة لقطة خارجية سلسلة إعادة التوجيه لم يتم التحقيق فيها
مؤشرات الأمان
SA Scamadviser Warnings
Registered contact email address is a free one Technical contact email address is a free one Administrative contact email address is a free one According to Tranco this site has a low rank High number of suspicious websites on this server This website may offer high-risk cryptocurrency services This website is (very) young. This website has been reported for spam by iQ Abuse Scan
The SSL certificate is valid This website is safe according to DNSFilter
GS Gridinsoft Analysis
Hosting SSL Certificate Financial Service Registration Form Recovery Service Wordpress Platform Young Domain

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
11/12

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. Cloudflare Radar

    تم حفظ فحص Cloudflare Radar · فتح الفحص

معلومات النطاق

النطاق
الخادم / ASN LiteSpeed · AS36352 AS-COLOCROSSING, US
سمعة عنوان IP IP abuse confidence 0/100 0 reports checked 19/06/2026
مسجّل النطاق Atak Domain TR(TR)
جهة الإبلاغ عن إساءة الاستخدامdomain@apiname.com, ohiraymond@gmail.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ cryptorecoveryconsultant.com →
عنوان IP 198.23.141.202 US
الموقع الجغرافيUS Buffalo, US
الشبكةAS36352 · HostPapa
التسجيلتم إنشاؤه 09/11/2024 Expires 09/11/2025
حالة HTTP502 Error
الوقت حتى أول تعذّر للوصول 198 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف09/08/2025
DOM Analysisanalyzed 24/03/2026DOM analysis score 10/1001 brand signal
Submitted URLhttps://cryptorecoveryconsultant.com/
خوادم الأسماءns1.sagaciousdns.comns2.sagaciousdns.com
رصد TLSفُحص في 06/04/2026
عنوان الصفحة
CRYPTO RECOVERY CONSULTANT
Impersonates
WhatsApp
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

3 / قام موردو الأمان 95 بوضع علامة على هذا المجال
View on VT
Last analyzed
alphaMountain.ai
Fortinet
Webroot

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

GridinsoftGridinsoft درجة الثقة 39/100الحالة: Suspiciousفتح المصدر
ScamAdviserScamAdviser درجة الثقة 1/100الحالة: Very Likely Unsafeفتح المصدر
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/cryptorecoveryconsultant.com"
  title="PhishDestroy threat report for cryptorecoveryconsultant.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.