الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 21. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

download[.]robinhooddesktopwallet[.]app

“Robinhood Wallet Desktop - Download for Windows | Official”

حكم التهديد حرجة 100/100 درجة الأدلة
التوفر لم يتم التحقق منها لا يتم تخزين أي استجابة حالية قاطعة
اكتشافات VirusTotal: 21/91 Spamhaus DBL: DBL_PHISH انتحال العلامة التجارية: Robinhood
08/07/2026 Robinhood
ملخص التقرير

download.robinhooddesktopwallet.app — لم يتم التحقق منها. انتحال العلامة التجارية: Robinhood; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 21/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25, CRDF); URLScan malicious verdict; Google Safe Browsing flagged; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 100/100. مسجّل النطاق: NiceNIC.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
62BF49F9
الدرجة
100/100

This domain, download.robinhooddesktopwallet.app, impersonates the official Robinhood Wallet desktop application to distribute malicious software designed to drain cryptocurrency from victims' wallets. The site presents itself as a legitimate download portal for Windows users, using the brand's name and visual elements to deceive visitors into installing malware. Once executed, this type of threat—known as a crypto drainer—can automatically transfer digital assets without the user's consent, leading to irreversible financial losses. The page title, 'Robinhood Wallet Desktop - Download for Windows | Official,' further reinforces the illusion of legitimacy, making it particularly dangerous for unsuspecting users seeking the real Robinhood Wallet software. Analysis indicates this domain is actively malicious, with 21 out of 95 security vendors on VirusTotal flagging it as harmful. The domain resolves to the IP address 45.74.7.185, a host frequently associated with phishing and malware distribution infrastructure. Google Safe Browsing has also classified this domain as phishing, corroborating the findings from independent security vendors. The registrar and creation date are not publicly disclosed in the current dataset, but the combination of vendor detections, IP reputation, and brand impersonation strongly suggests a coordinated effort to exploit Robinhood's user base. The domain remains active as of the latest verification, increasing the urgency for potential victims to take protective measures. If you or someone you know visited download.robinhooddesktopwallet.app and downloaded or installed any files, immediate action is required. First, disconnect the affected device from the internet to prevent further data exfiltration or unauthorized transactions. Do not interact with any cryptocurrency wallets or enter credentials on the device until it has been scanned with up-to-date antivirus software. If a wallet was connected or credentials were entered, assume they are compromised and transfer any remaining assets to a new, secure wallet. Monitor all linked accounts for unauthorized activity and enable multi-factor authentication where possible. Report the incident to Robinhood's official support channels and consider filing a report with local cybercrime authorities to aid in tracking the infrastructure behind this threat.

VirusTotal
VirusTotal
21 det.
رادار CF
ضار
شهادة TLS
Let's Encrypt / YR2
العمر
1 mo New
الحالة المرصودة
لم يتم التحقق منها
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 21 / 91 URLQuery لم يتم التحقق منها PhishStats لم يتم التحقق منها OTX no community references رادار CF provider verdict: malicious URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 47d WHOIS 1 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات Registrar context
CF Cloudflare Radar Verdict ضار
Phishing
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
12/14

حالة قوائم الحظر العامة

لقطة محفوظة

عنوان الصفحة
Robinhood Wallet Desktop - Download for Windows | Official
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt / YR2 · valid for 47 days

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: Robinhood report ↗
Google Safe Browsing تم وضع علامة عليها Social engineering checked 08/07/2026
الخادم / ASN nginx/1.24.0 · AS202412 Omegatech LTD
سمعة عنوان IP abuse score 0/100 0 reports checked 10/08/2026
Registrar (base domain) NiceNIC RU(RU) PhishDestroy Investigation
جهة الإبلاغ عن إساءة الاستخدامabuse@virtualine.org
البحث في قاعدة بيانات WHOISICANN RDAP لـ robinhooddesktopwallet.app →
عنوان IP 45.74.7.185 GB
الموقع الجغرافيGB London, GB
الشبكةAS202412 · Virtualine Technologies
Registration (base domain)robinhooddesktopwallet.app · تم إنشاؤه 08/07/2026 (41d · New)
Elapsed Since First Report 4h
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: لم يتم التحقق منها.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف08/07/2026
DOM Analysisanalyzed 08/07/2026score 100/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://download.robinhooddesktopwallet.app/
خوادم الأسماءraquel.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 07/07/2026scanned 08/07/2026
ICANN OVERSIGHT Registration: robinhooddesktopwallet.app

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain robinhooddesktopwallet.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.

Latest Classified Outcome 2026-08-18 03:21:15 UTC

Primary outcome Registration hold observed reason: Registrar clientHold 95% confidence
Attribution NICENIC INTERNATIONAL GROUP CO., LIMITED mechanism: Registrar clientHold source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Registrar clientHold
Latest HTTP observation غير معروف Origin unreachable Http 5xx 20% 2026-08-18 02:32:02 UTC
RDAP registration Registrar clientHold NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientHoldclientTransferProhibited expires 2027-07-07 12:57:37 UTC checked 2026-08-18 03:21:15 UTC
Registrar action marker verified clientHold marker NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 causal link to our report not established
Observed timeline last reachable: 2026-07-09 02:08:15 UTC current episode first observed: 2026-08-05 01:45:38 UTC observed RIP window: 2026-07-09 02:08:15 UTC → 2026-08-05 01:45:38 UTC · 647.62h midpoint estimate ≈ 2026-07-22 13:56:56 UTC · precision low · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
التقنيات · 3 identified
Tailwind CSS
UI frameworks

Tailwind is a utility-first CSS framework.

tailwindcss.com ثقة 100٪
Nginx
Web servers Reverse proxies

Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.

nginx.org ثقة 100٪
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org ثقة 100٪
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

21 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed
alphaMountain.ai
BitDefender
Chong Lua Dao
Cluster25
CRDF
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Google Safebrowsing
Gridinsoft
كاسبرسكي
LevelBlue
Lionic
MalwareURL
OpenPhish
Seclookup
SOCRadar
سوفوس
Webroot

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/download.robinhooddesktopwallet.app"
  title="PhishDestroy threat report for download.robinhooddesktopwallet.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.