dev[.]go-to[.]rest
فحص التصيد والأمان للنطاق dev.go-to.rest
“GTR”
dev.go-to.rest — المحتوى غير متوفر (HTTP 404). انتحال العلامة التجارية: Telegram; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VT 15/93 (Abusix, Criminal IP, alphaMountain.ai, Certego, Cluster25); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 0; PD 100/100. مسجّل النطاق: Name.com.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy first observed dev.go-to.rest on Feb 2, 2026. A positive finding was recorded by VirusTotal. Evidence score: 100/100.
VirusTotal recorded 15 detections among 93 engines: Abusix, Criminal IP, alphaMountain.ai, Certego, Cluster25, CRDF, Fortinet, Gridinsoft on Jul 18, 2026 at 18:45 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0) on Mar 28, 2026 at 11:49 UTC. PhishStats returned no feed match on Mar 3, 2026 at 08:07 UTC.
HTTP 404 was recorded on Aug 7, 2026 at 01:55 UTC; content was unavailable. Registration records list Name.com, Inc. as the registrar. At collection time, the domain resolved to 37.27.6.109. Collected metadata identifies Telegram as the apparent target. Captured page title: “GTR”. PhishDestroy classified the observed content as Brand Impersonation. DOM analysis completed on Apr 23, 2026 at 07:20 UTC; stored DOM score 10/100. IoC extraction completed on Aug 2, 2026 at 04:01 UTC; stored 0 format-validated wallet addresses and 1 Telegram indicator.
Stored full analysis23/07/2026
The domain dev.go-to.rest was observed by PhishDestroy and classified as a brand‑impersonation campaign targeting Telegram users. Registration data shows the domain was created on 21 February 2026 through Name.com, Inc., and it resolves to the IPv4 address 37.27.6.109, which is assigned to the Hetzner Online GmbH network in Finland (AS 24940). The hosting provider is identified by the IP’s autonomous system, confirming the infrastructure is located in Europe. DNS resolution is handled by Cloudflare, using the authoritative nameservers tim.ns.cloudflare.com and sue.ns.cloudflare.com.
No TLS certificate was presented when the host was queried, and the HTTP response returned a 404 status, indicating the web resource is not publicly serving content at the time of analysis. The page title reported by scanners is “GTR”, which does not reference the targeted brand and suggests the payload page has been removed or is otherwise inaccessible. Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on a single external blocklist, reinforcing the malicious assessment. VirusTotal scans recorded 15 detections out of 93 participating security vendors, confirming that multiple anti‑malware engines flag the domain as malicious.
The overall risk rating is elevated, and the current operational status is offline, meaning the site is no longer reachable but the infrastructure may be reused. Defenders should continue to block the domain and its associated IP address, add the domain to internal URL filtering policies, and monitor for newly registered domains that reuse the same registrar, nameserver configuration, or hosting ASN. Continuous threat‑intel feeds should be consulted for any reappearance of the same indicators, and any inbound traffic to 37.27.6.109 should be inspected for residual malicious payloads.
مؤشرات الأمان
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: go-to.rest
الاعتماد وسياق RAA
الاعتماد وسياق RAA
حصلت ICANN على أموالها. أما المساءلة فلم تصل.
For the registrable domain go-to.rest behind this subdomain, the registrar above operates under an ICANN contract. ICANN collects annual, variable and transaction-based fees tied to registrations, renewals and transfers.
الاعتماد: جرت الاستفادة منه مالياً. المساءلة: يُرجى التحقق مرة أخرى لاحقاً.
ثم يبدأ السحر: تكتب ICANN البند RAA §3.18، ويتولى المسجّل التحقيق في إساءة الاستخدام داخل قاعدة عملائه، ويقدّم الضحايا الأدلة مجاناً، بينما تنتظر كل طبقة أن يتحرك طرف آخر. إذا كان ذلك يجعل الضحايا يشعرون بمزيد من الأمان، فممتاز—لقد أدّت الفاتورة مهمتها.
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
حول هذا التقرير: dev.go-to.rest
يقدم هذا التقرير أحدث الأدلة المخزنة المتاحة لـ PhishDestroy. يتم عرض الطوابع الزمنية للمصدر حيثما كان ذلك متاحًا؛ يمكن أن تتغير أحكام التوفر والبائعين بعد التجميع.
عرض الموقع الذي تم التقاطه عنوان الصفحة “GTR” وربما ينتحل شخصية Telegram.
اعتبارًا من 07/08/2026، كان لدى dev.go-to.rest اكتشافات من محركات الأمان 15.
إذا كنت تعتقد أن هذه القائمة غير دقيقة، تقديم استئناف. للتعرف على منهجيتنا، قم بزيارة صفحة الأسئلة الشائعة.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب