الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 12. قوائم الحظر العامة التي تبلغ عن تطابق: 1. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

doc-protect[.]cloud

فحص التصيد والأمان للنطاق doc-protect.cloud

حكم التهديد حرجة 96/100 درجة الأدلة
التوفر آخر نشاط معروف لم تكن متاحة من قبل؛ آخر ملاحظة كانت قابلة للوصول
إشارات الخطر
اكتشافات VirusTotal: 12/91 تطابقات القائمة السوداء المخزنة: 1 نوع الاحتيال: Credential Phishing آخر نشاط معروف
12/91 VT OTX: 1 ref 15/06/2026 غير متاح منذ 09/08/2026 1 Blocklist التصيد الاحتيالي للحصول على بيانات الاعتماد CDN
ملخص التقرير

doc-protect.cloud — آخر نشاط معروف (HTTP 200). نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); 1 external blocklist match (CryptoFirewall); PhishDestroy score 96/100. مسجّل النطاق: GMO Internet.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
35EB3515
الدرجة
96/100

Analysis of the domain doc-protect.cloud indicates an active credential phishing campaign as of July 13, 2026. The domain was registered on May 15, 2026, through GMO Internet, Inc. d/b/a Onamae.com, a registrar frequently associated with high-risk domains. Infrastructure analysis reveals the domain resolves to the IP address 172.104.203.186, hosted on Linode infrastructure in Germany. Nameservers hehua.ns.giantpanda.com and qizai.ns.giantpanda.com are utilized, a pattern observed in other phishing operations leveraging third-party DNS providers for resilience. The domain is flagged by 11 of 92 security vendors on VirusTotal, a detection rate consistent with confirmed phishing activity. It appears on two security blocklists, including PhishDestroy and CryptoFirewall, and has been documented in one AlienVault OTX threat intelligence pulse. The Gridinsoft trust score of 0/100 further corroborates its malicious classification. The page title 'Checking your browser...' suggests the use of a browser-checking or fingerprinting mechanism, commonly employed in phishing kits to filter targets or evade automated analysis. While the exact brand or service being impersonated remains unconfirmed due to the absence of detailed page content analysis, the scam type is classified as credential phishing based on available intelligence. The SSL certificate, issued by Let's Encrypt (R12), does not mitigate the threat, as phishing domains frequently use valid certificates to appear legitimate. Defenders are advised to block the domain and its resolving IP at the network level, monitor for related infrastructure (e.g., nameservers, hosting provider), and alert users to potential credential harvesting attempts originating from this campaign. Continuous monitoring is recommended, as the domain remains active and may evolve in tactics or targeting.

VirusTotal
VirusTotal
12 det.
OTX references
شهادة TLS
منتهية الصلاحية أو غير متحقق منها -34d
العمر
3 mo New
الحالة المرصودة
آخر نشاط معروف 200
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 12 / 91 URLQuery لم يتم التحقق منها PhishStats لم يتم التحقق منها OTX 1 community reference رادار CF no data URLScan capture not submitted URLScan verdict التقييم غير متاح حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 3 mo old لقطة شاشة لم يتم تسجيله سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
7/9

حالة قوائم الحظر العامة

معلومات النطاق

النطاق
الخادم / ASN openresty/1.27.1.2 · AS63949 Akamai Connected Cloud
IP Context Akamai shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق GMO Internet
عنوان IP 172.104.203.186 CDN
الموقع الجغرافيDE Frankfurt am Main, DE
الشبكةAS63949 · Linode
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 15/05/2026 (85d · New) Expires 05/11/2026
Elapsed Since First Report 34 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: آخر نشاط معروف.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
حالة HTTP200
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف15/06/2026
خوادم الأسماءqizai.ns.giantpanda.com
TLS Fingerprint
TLS Observationvalid from 07/04/2026scanned 17/05/2026
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

12 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 11 detections
ADMINUSLabs
alphaMountain.ai
BitDefender
CyRadar
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
كاسبرسكي
Lionic
SOCRadar
سوفوس

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/doc-protect.cloud"
  title="PhishDestroy threat report for doc-protect.cloud"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.