MALICIOUS — CRITICAL
فحص التصيد والأمان للنطاق fbiamlform.org
fbiamlform[.]
This domain, fbiamlform.org, is identified as a high-risk phishing site designed to deceive cryptocurrency users.
- VirusTotal
- 13/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
fbiamlform.org — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: ["roblox"]; نوع الاحتيال: Aml Scam. ملخص الأدلة: VirusTotal 13/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, ESET); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 89/100. مسجّل النطاق: Global Domain Group.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
This domain, fbiamlform.org, is identified as a high-risk phishing site designed to deceive cryptocurrency users. Analysis indicates it presents a fraudulent interface mimicking legitimate wallet verification or account recovery pages, likely prompting visitors to enter sensitive credentials such as private keys, seed phrases, or login details. The intent is to harvest this information for unauthorized access to digital assets, leading to potential financial theft or account compromise. Infrastructure analysis reveals multiple technical indicators confirming its malicious nature. The domain was registered on April 10, 2026, through Global Domain Group LLC, a registrar frequently associated with suspicious registrations. It resolves to the IP address 188.114.97.3 and is currently flagged by 16 out of 95 security vendors on VirusTotal. Additionally, it appears on three security blocklists and was included in one threat intelligence pulse on AlienVault OTX. The page title, 'Just a moment...,' is a common obfuscation technique used to delay or mislead users while malicious scripts execute in the background. If you visited fbiamlform.org or interacted with its content, immediate action is required. Disconnect the device from the network to prevent further data exfiltration. Clear all browser data, including cookies and cached files, to remove any residual tracking elements. Scan the system using updated security tools to detect and remove potential malware. If credentials were entered, revoke access to all associated accounts, enable multi-factor authentication where available, and monitor for unauthorized transactions. Report the incident to relevant financial or cryptocurrency platforms to initiate protective measures. Users should also verify the legitimacy of any unexpected communications prompting visits to such domains.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.