الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 5. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
REGISTRAR NEGLIGENCE · EGREGIOUS NICENIC INTERNATIONAL GROUP CO., LIMITED was notified 4 months ago — the threat is still operational.
Why this matters — ICANN RAA §3.18 obligation

On PhishDestroy delivered an evidence-backed abuse report to abuse@nicenic.net with the evidence stored for the case at that time. More than 4 months later, the phishing infrastructure remains reachable .

Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.

Elapsed since first report
4 months
Reports sent
1
Latest case ID
PD-20260404-BD3E38
Current status
Serving traffic (alive)
أمن المجال وذكاء التهديدات

echobit[.]global

فحص التصيد والأمان للنطاق echobit.global

“EchoBit - Trading Exchange”

حكم التهديد حرجة 70/100 درجة الأدلة
التوفر خطأ في الخادم آخر استجابة مخزنة كانت غير حاسمة
إشارات الخطر
اكتشافات VirusTotal: 5/91 Spamhaus DBL: DBL_PHISH نوع الاحتيال: Fake Exchange
5/91 VT OTX: 1 ref 04/04/2026 Fake Exchange 1 Report Sent CDN
ملخص التقرير

echobit.global — خطأ في الخادم (HTTP 521). نوع الاحتيال: Fake Exchange. ملخص الأدلة: VT 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar); URLQuery 0; URLScan no malicious verdict; GSB no flag; Spamhaus DBL_PHISH; BL 0; PD 70/100. مسجّل النطاق: NiceNIC.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
082F5270
الدرجة
70/100

echobit.global entered the PhishDestroy evidence set on Apr 4, 2026. The stored content classification is fake exchange. The assembled evidence scores 70/100 (high).

Two independent sources are positive: VirusTotal and Spamhaus DBL. VirusTotal recorded 5 detections among 91 engines: alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar on Aug 5, 2026 at 14:30 UTC. Spamhaus DBL: DBL_PHISH on Jul 13, 2026 at 22:31 UTC. The evidence is not unanimous. AlienVault OTX listed 1 community pulse reference (not vendor detections) on Apr 6, 2026 at 06:32 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 18:20 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Jun 26, 2026 at 09:28 UTC. URLScan completed without a malicious verdict (score 0).

HTTP 521 server error was recorded on Aug 7, 2026 at 10:44 UTC. Latest classified outcome: unknown; cause probe inconclusive on Aug 7, 2026 at 00:48 UTC. Registration records for the domain list NICENIC INTERNATIONAL GROUP CO., LIMITED as the registrar and Apr 4, 2026 as the creation date. Registration preceded first observation by 0 days. At collection time, the hostname resolved to 104.21.62.20 on AS13335 (Cloudflare, Inc.). The recorded endpoint location is Toronto, CA. The stored server header is cloudflare. Captured page title: “EchoBit - Trading Exchange”. The evidence archive retains 1 visual capture from PhishDestroy. IoC extraction completed on Jul 29, 2026 at 02:07 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators. TLS metadata lists Let's Encrypt as the certificate issuer with validity through Jun 28, 2026; checked Apr 5, 2026 at 00:07 UTC.

No target brand has been confirmed from stored page content; hostname wording alone is not treated as brand evidence. Taken together, the page content and independent findings support classifying this hostname as fake exchange.

VirusTotal
VirusTotal
5 det.
OTX references
Gridinsoft
0/100
شهادة TLS
Let's Encrypt
العمر
4 mo
الحالة المرصودة
خطأ في الخادم 521
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات VirusTotal 5 / 91 URLQuery تم تخزين التقرير - الحكم التفصيلي معلق PhishStats لم يتم التحقق منها OTX 1 community reference رادار CF no data URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 61d WHOIS 4 mo old لقطة شاشة لقطة خارجية سلسلة إعادة التوجيه لم يتم التحقيق فيها Gridinsoft 0/100
استخبارات أمن الشبكات Registrar Integrity Alert
High-Risk Registrar NiceNIC
PhishDestroy audit found that over 90% of domains registered through NiceNIC are associated with illegal content. This registrar systematically ignores abuse reports and its primary clientele consists of CIS-region scam operators. We have not identified a single legitimate project hosted on this registrar.
NiceNIC Verdict Full Investigation

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
13/14
Initial Abuse Report (#1)
Sent to 3 abuse contacts at NICENIC INTERNATIONAL GROUP CO., LIMITED with forensic evidence
abuse@nicenic.netabuse@identitydigital.comcompliance@icann.org
09/04/2026

حالة قوائم الحظر العامة

لقطة محفوظة

عنوان الصفحة
EchoBit - Trading Exchange
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 61 days

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق NiceNIC RU(RU) PhishDestroy Investigation
جهة الإبلاغ عن إساءة الاستخدامabuse@nicenic.net
البحث في قاعدة بيانات WHOISICANN RDAP لـ echobit.global →
عنوان IP 104.21.62.20 CDN
الموقع الجغرافيCA Toronto, CA
الشبكةAS13335 · Cloudflare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 04/04/2026 (125d) Expires 30/03/2027
حالة HTTP521 Error
Elapsed Since First Report 18 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: خطأ في الخادم.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف04/04/2026
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://echobit.global/
خوادم الأسماءcarla.ns.cloudflare.comgerardo.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 30/03/2026scanned 05/04/2026
Case ID
ICANN OVERSIGHT

الاعتماد وسياق RAA

حصلت ICANN على أموالها. أما المساءلة فلم تصل.

بالنسبة إلى نطاق gTLD هذا، يعمل المسجّل المذكور أعلاه بموجب عقد مع ICANN. وتحصّل ICANN رسوماً سنوية ومتغيرة ورسومًا قائمة على المعاملات مرتبطة بعمليات التسجيل والتجديد والنقل.

الاعتماد: جرت الاستفادة منه مالياً. المساءلة: يُرجى التحقق مرة أخرى لاحقاً.

ثم يبدأ السحر: تكتب ICANN البند RAA §3.18، ويتولى المسجّل التحقيق في إساءة الاستخدام داخل قاعدة عملائه، ويقدّم الضحايا الأدلة مجاناً، بينما تنتظر كل طبقة أن يتحرك طرف آخر. إذا كان ذلك يجعل الضحايا يشعرون بمزيد من الأمان، فممتاز—لقد أدّت الفاتورة مهمتها.

ملاحظة ساخرة عن المساءلة لا يُرسل أي شيء تلقائياً.

Latest Classified Outcome 2026-08-07 02:48:04 UTC

Primary outcome غير معروف reason: Probe Inconclusive 20% confidence
Attribution source: Current Http Probe
Evidence layers Availability: Unreachable Content: Unknown DNS: Resolved Registration: Active
Latest HTTP observation غير معروف Probe Inconclusive 20% 2026-08-07 02:48:04 UTC
RDAP registration نشط NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientTransferProhibited expires 2027-03-30 11:42:43 UTC checked 2026-08-05 19:02:28 UTC
Observed timeline last reachable: 2026-08-07 02:48:04 UTC
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

5 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
alphaMountain.ai
CRDF
Fortinet
Gridinsoft
SOCRadar
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of echobit.global · checked Jun 26, 2026

74
Needs Work
Performance
FCP
0.9s
First Contentful Paint
LCP
5.59s
Largest Contentful Paint
CLS
0.035
Cumulative Layout Shift
TBT
253ms
Total Blocking Time
SI
3.07s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/echobit.global"
  title="PhishDestroy threat report for echobit.global"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.