الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

facebook[.]bora-bora[.]dk

“Bora Bora - Dans og visuelt teater | Aarhus | Facebook”

حكم التهديد حرجة 86/100 درجة الأدلة
التوفر مغطى بعباءة · يمكن الوصول إليه تمت ملاحظة إمكانية الوصول من خلال عمليات فحص إخفاء الهوية
اكتشافات VirusTotal: 2/91 انتحال العلامة التجارية: Facebook آخر نشاط معروف
26/02/2026 Facebook

اكتشاف محفوظ

تنبيه إخفاء المحتوى

نوع الإخفاء
bot_redirect_safe
درجة الإخفاء
4/6
العنوان المعروض للماسح302 Found
العنوان المعروض للزائرBora Bora - Dans og visuelt teater | Aarhus | Facebook

ملخص الأدلة

حرج
Evidence score
86/100

facebook.bora-bora.dk is a newly registered domain (created 21 Feb 2026) that currently hosts a brand‑impersonation page targeting Facebook. The page title “Bora Bora - Dans og visuelt teater | Aarhus | Facebook” mimics the layout of a Facebook event or community, indicating an attempt to deceive users into believing the content is hosted by Facebook. The domain is classified as high‑risk and remains active as of 12 Jul 2026.

Technical inspection shows the domain resolves to the IPv6 address 2a03:2880:f177:185:face:b00c:0:25de, which maps to a German network owned by AS32934, the Facebook, Inc. infrastructure. The site serves over HTTPS with a Let’s Encrypt certificate (issuer E7) and returns an HTTP 302 redirect, a common technique to steer victims to a final malicious landing page. The page title and SSL details together provide enough visual cues for social‑engineering attacks.

Threat intelligence indicates that 3 of 95 VirusTotal scanners have flagged the domain, and it appears on one external blocklist (PhishDestroy). Gridinsoft assigns a trust score of 0 / 100, reinforcing the malicious assessment. The limited number of vendor detections leaves some uncertainty regarding the exact payload or credential‑harvesting mechanism, but the presence of a brand‑impersonation tag and the redirection behavior strongly suggest a phishing campaign.

Defenders should prioritize blocking facebook.bora-bora.dk at the DNS layer and add the IPv6 address to network‑level deny lists. Monitoring for outbound connections to this address and for HTTP 302 responses returning Facebook‑related titles will help detect exploitation attempts. Users should be reminded not to follow links that appear to originate from Facebook but contain unexpected domain names. Continuous updating of threat‑intel feeds will ensure that any future changes to the site are captured promptly.

VirusTotal
VirusTotal
2 det.
DNS Security
1/14
شهادة TLS
منتهية الصلاحية أو غير متحقق منها
العمر
6 mo
الحالة المرصودة
مغطى بعباءة · يمكن الوصول إليه HTTP 302
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 2 / 91 URLQuery لم يتم التحقق منها PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 1/14 TLS منتهية الصلاحية أو غير متحقق منها WHOIS 6 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
DNS Provider Blocks 1 / 14
Brand Facebook

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
11/13

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. Cloudflare Radar

    تم حفظ فحص Cloudflare Radar · فتح الفحص

  2. Cloudflare Radar

    تم حفظ فحص Cloudflare Radar · فتح الفحص

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN AS32934 FACEBOOK, US
سمعة عنوان IP 1 report
عنوان IP 2a03:2880:f177:185:face:b00c:0:25de DE
الموقع الجغرافيDE Frankfurt am Main, DE
الشبكةAS32934 · Facebook, Inc.
Registration (base domain)bora-bora.dk · تم إنشاؤه 21/02/2026 (171d)
حالة HTTP302 Found (Temporary)
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف26/02/2026
DOM Analysisanalyzed 09/07/2026DOM analysis score 86/100
رصد TLSفُحص في 15/03/2026
عنوان الصفحة
Bora Bora - Dans og visuelt teater | Aarhus | Facebook
شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن Let's Encrypt / E7
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

2 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 3 detections
Forcepoint ThreatSeeker
Gridinsoft

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/facebook.bora-bora.dk"
  title="PhishDestroy threat report for facebook.bora-bora.dk"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>