الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref ED9FD4B7

MALICIOUS — CRITICAL

eqpay[.]icu

eqpay.icu is an active fake payment scam domain designed to deceive users into divulging financial credentials under the guise of a legitimate transaction service.

71/100 evidence score · Critical
VirusTotal
3/94
Blocklists
No stored match
التوفر
مغطى بعباءة · يمكن الوصول إليه · HTTP 502
Report / Add Evidence Appeal this listing
2026-04-21 11:24 UTCمغطى بعباءة · يمكن الوصول إليه · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 3. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
Jump to section
ملخص التقرير

eqpay.icu — مغطى بعباءة · يمكن الوصول إليه (HTTP 502). ملخص الأدلة: VirusTotal 3/94 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft); URLQuery 1 det.; cloaking observed; PhishDestroy score 71/100. مسجّل النطاق: NiceNIC.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref ED9FD4B7

eqpay.icu is an active fake payment scam domain designed to deceive users into divulging financial credentials under the guise of a legitimate transaction service. Threat analysis reveals it mimics payment platforms to harvest login details, credit card numbers, or other sensitive information through spoofed checkout pages. The domain’s infrastructure and naming suggest an intentional attempt to exploit trust in established payment processors, leveraging urgency (e.g., 'eqpay') to bypass user scrutiny. Security researchers have linked this pattern to opportunistic credential harvesting campaigns targeting consumers familiar with payment systems like PayPal or Stripe.

This domain was flagged by PhishDestroy under investigation as a generic phishing site due to critical red flags: it resolves to IP 23.236.186.134 and currently shows a concerning 3/95 VirusTotal detection rate—indicating zero antivirus engines have identified its malicious nature despite active hosting. The domain was registered on April 18, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar often used to obscure the origin of fraudulent domains. Notably, its SSL certificate issued by Let’s Encrypt does not validate legitimacy, as threat actors increasingly exploit free certificates to enhance believability. With no current blocklist presence, users remain unprotected unless proactive measures are taken.

If you visited eqpay.icu, immediately inspect any entered credentials or payment details on a separate device, then change passwords across critical accounts and monitor for fraudulent transactions. Do NOT re-enter sensitive data, and treat all forms on the site as compromised. Report the domain to your cybersecurity team or use tools like PhishDestroy’s database to flag it. Block the IP 23.236.186.134 in your firewall and DNS if possible. Stay vigilant—new phishing domains emerge daily, and only verified sources should be trusted for financial transactions.

VirusTotal
VirusTotal
3 det.
URLQuery
URLQuery
1 det.
شهادة TLS
Let's Encrypt
العمر
4 mo
الحالة المرصودة
مغطى بعباءة · يمكن الوصول إليه 502
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات12 recorded checks
VirusTotal 3 / 94 URLQuery 1 det. PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 12 تم الفحص — لا يوجد حظر TLS valid certificate, 87d WHOIS 4 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات Registrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
11/12
Sent Report Recorded
Stored sent-report record for registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, hosting provider, 3 abuse contacts
abuse-system@servermania.comabuse@servermania.comabuse@nicenic.net
21/04/2026

حالة قوائم الحظر العامة

لقطة محفوظة

عنوان الصفحة
Deposito per l'attivazione del trading
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 87 days

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN nginx · AS55286 B2 Net Solutions Inc.
سمعة عنوان IP abuse score 0/100 0 reports checked 13/07/2026
مسجّل النطاق NiceNIC RU(RU) PhishDestroy Investigation
جهة الإبلاغ عن إساءة الاستخدامabuse-system@servermania.com, abuse@servermania.com, abuse@nicenic.net
البحث في قاعدة بيانات WHOISICANN RDAP لـ eqpay.icu →
عنوان IP 23.236.186.134 NL
الموقع الجغرافيNL Halfweg, NL
الشبكةAS55286 · ServerMania Inc
التسجيلتم إنشاؤه 21/04/2026 (110d)
حالة HTTP502 Error
Cloaking Cloaking Detected Status split · score 4/6
dead_http: raw=http_502; http=502; via=http_proxy
checked 09/08/2026
Elapsed Since First Report 23 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: مغطى بعباءة · يمكن الوصول إليه.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف21/04/2026
DOM Analysisanalyzed 29/07/2026score 71/100
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://eqpay.icu/
خوادم الأسماءns2.dnspodsag.com
TLS Fingerprint
TLS Observationvalid from 18/04/2026scanned 21/04/2026
TLS SAN Domainswww.eqpay.icu
Case ID
نطاق SHORTDOT · أدلة عامة .icu

ShortDot zone evidence

The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.

ShortDot SA · Luxembourg 7 مناطق · أدلة المناطق الكاملة تُحدّث يوميًا افتح مستودع أدلة ShortDot
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.

Latest Classified Outcome 2026-08-08 03:53:53 UTC

Primary outcome Registration hold observed reason: Registrar clientHold 95% confidence
Attribution NICENIC INTERNATIONAL GROUP CO., LIMITED mechanism: Registrar clientHold source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Registrar clientHold
Latest HTTP observation غير معروف Origin unreachable Http 5xx 20% 2026-08-09 01:34:47 UTC
RDAP registration Registrar clientHold NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientHoldclientTransferProhibited expires 2027-04-18 23:59:59 UTC checked 2026-08-08 03:53:53 UTC
Registrar action marker verified clientHold marker NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 causal link to our report not established
Observed timeline last reachable: 2026-06-16 22:16:37 UTC current episode first observed: 2026-08-05 01:45:38 UTC observed RIP window: 2026-06-16 22:16:37 UTC → 2026-08-05 01:45:38 UTC · 1,179.48h midpoint estimate ≈ 2026-07-11 12:01:07 UTC · precision very low · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
التقنيات · 3 identified
PHP
Programming languages

PHP is a general-purpose scripting language used for web development.

php.net ثقة 100٪
Nginx
Web servers Reverse proxies

Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.

nginx.org ثقة 100٪
jQuery
JavaScript libraries

jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.

jquery.com ثقة 100٪
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

3 / قام موردو الأمان 94 بوضع علامة على هذا المجال
View on VT
Last analyzed
alphaMountain.ai
Forcepoint ThreatSeeker
Gridinsoft
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260421-45A676 Recipient: abuse@servermania.com
Page title stored with report: Deposito per l'attivazione del trading
نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/eqpay.icu"
  title="PhishDestroy threat report for eqpay.icu"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.