daves-pizzas[.]xyz
“$PIZZA Distribution”
daves-pizzas.xyz — خطأ في الخادم (HTTP 502). انتحال العلامة التجارية: Coinbase; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 12/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); 1 external blocklist match (ScamSniffer); PhishDestroy score 91/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of daves-pizzas.xyz indicates a confirmed brand‑impersonation campaign targeting Coinbase users. The domain was registered on August 30, 2025 through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to the IPv6 address 2606:4700:3032::ac43:9cf2, which is hosted by Cloudflare (AS13335) in the United States. An SSL certificate labelled WE1 is present, providing transport‑level encryption but offering no authentication of the underlying content. The site’s HTTP response is currently offline, and the page title returned during the brief live window was “$PIZZA Distribution,” a name that does not correspond to any known Coinbase service.
The campaign is classified as a crypto‑scam and explicitly impersonates the Coinbase brand, as reflected in the intelligence tag “brand target: coinbase.” Reputation services assign extremely low trust scores (Scamadviser 1/100, Gridinsoft 0/100), and the domain appears on two independent blocklists, PhishDestroy and ScamSniffer. VirusTotal analysis shows that twelve of ninety‑three scanning engines flagged the domain as malicious, reinforcing the suspicion of malicious intent. At present, no additional artefacts such as malicious payloads, credential‑stealing forms, or redirection chains have been publicly disclosed, leaving the exact content and victim‑interaction flow uncertain.
Defenders should prioritize immediate blocking of the domain and its hosting IP at network perimeter devices, update endpoint protection signatures to include the observed VirusTotal detections, and monitor for newly registered domains that share the same registrar or similar naming patterns. Continuous observation of Cloudflare‑hosted IPv6 ranges associated with this ASN is advised, as threat actors frequently leverage the same infrastructure for rapid re‑deployment.
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-05 18:51:46 UTC
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب