deltaf254-lab[.]pages[.]dev
فحص التصيد والأمان للنطاق deltaf254-lab.pages.dev
“AMERICA IS BACK | $AIB”
deltaf254-lab.pages.dev — آخر نشاط معروف (HTTP 200). ملخص الأدلة: VirusTotal 3/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 84/100. مسجّل النطاق: Cloudflare Pages.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis indicates that the domain deltaf254-lab.pages.dev is actively engaged in cryptocurrency-themed phishing as of July 19, 2026. The domain resolves to IP address 172.66.44.147, which is hosted on Cloudflare infrastructure in Canada. The page title, 'AMERICA IS BACK | $AIB,' suggests a focus on a cryptocurrency asset or token, though the specific brand or project being impersonated is not confirmed in available data. The domain is registered through Cloudflare Pages and uses a Let's Encrypt SSL certificate (identifier YE2), which is consistent with both legitimate and malicious sites leveraging free certificate authorities. The domain appears on three security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, indicating detection by multiple independent threat intelligence sources. Two of 91 security vendors on VirusTotal flag the domain as malicious, though the absence of broader detection does not preclude its classification as a threat. The HTTP status code 200 confirms the site is currently accessible. Infrastructure analysis reveals no anomalous registration patterns, but the use of Cloudflare Pages aligns with common phishing tactics to evade takedowns and obscure hosting origins. Defenders should treat this domain as high-risk and prioritize blocking it at the network and endpoint levels. Given its association with cryptocurrency-themed phishing, wallet providers and exchanges are advised to monitor for references to this domain in transaction metadata or user reports. Further investigation into the $AIB token or project may clarify the intended target, but current evidence supports immediate mitigation actions. The domain remains active, and no takedown efforts have been observed as of the report date.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
المراجع المتقاطعة لاستخبارات التهديدات · source references
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب