cryptoslam-ir[.]io
“Cryptoslam”
cryptoslam-ir.io — المحتوى غير متوفر (HTTP 502). نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 10/94 (ADMINUSLabs, alphaMountain.ai, CRDF, ESET, Emsisoft); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 80/100. مسجّل النطاق: Dynadot.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
On July 25, 2026 analysts observed that the domain cryptoslam-ir.io is currently offline but was previously associated with a high‑risk generic phishing campaign. The domain was registered through Dynadot LLC and its creation date is recorded as January 27, 2026. Infrastructure analysis shows the domain resolved to the IP address 104.21.27.163, which belongs to AS13335 operated by Cloudflare, Inc., located in the United States. DNS resolution used the Cloudflare authoritative nameservers ali.ns.cloudflare.com and eric.ns.cloudflare.com, indicating the use of Cloudflare’s CDN and security services.
The web application stack identified Vue.js, HTTP/3, Cloudflare Browser Insights, and HTTP Strict Transport Security (HSTS), suggesting a modern front‑end framework hosted behind Cloudflare’s edge. Reputation data from Gridinsoft assigned a trust score of 0 out of 100, reflecting an extremely low confidence in the domain’s legitimacy. VirusTotal scans reported that ten of ninety‑four security vendors flagged the domain as malicious, reinforcing the suspicion of malicious intent. Independent blocklist monitoring recorded the domain on three security blocklists, and it was explicitly blocked by PhishDestroy, MetaMask, and SEAL, indicating recognition by multiple anti‑phishing and crypto‑wallet security solutions.
The page title returned by the server was "Cryptoslam," but no further content analysis is available. Given the combination of a newly created domain, low trust score, multiple vendor detections, and blocklist inclusion, defenders should continue to monitor any residual DNS or IP activity linked to 104.21.27.163, enforce blocklist rules that already contain cryptoslam‑ir.io, and consider adding the domain to internal deny lists.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | cryptoslam-ir.io/assets/index.3042f21d.js |
malware | Detects file containing Telegram Bot API |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 5 identified
Progressive JavaScript framework for building user interfaces.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of cryptoslam-ir.io · checked Mar 16, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب