firerounds[.]com
فحص التصيد والأمان للنطاق firerounds.com
“FIREROUNDS”
firerounds.com — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Dota 2; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VT 11/93 (alphaMountain.ai, CRDF, CyRadar, ESET, Fortinet); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 0; PD 88/100. مسجّل النطاق: REGRU-RU.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy first observed firerounds.com on Jan 24, 2026. A positive finding was recorded by VirusTotal. Evidence score: 88/100.
VirusTotal recorded 11 detections among 93 engines: alphaMountain.ai, CRDF, CyRadar, ESET, Fortinet, G-Data, Gridinsoft, Lionic on Feb 23, 2026 at 11:45 UTC. AlienVault OTX listed 14 community pulse references (not vendor detections) on Mar 1, 2026 at 11:12 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 10:20 UTC. URLQuery recorded no positive detection on Jan 24, 2026 at 21:17 UTC. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0) on Mar 28, 2026 at 12:30 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:15 UTC; content was unavailable. Registration records list REGRU-RU as the registrar. At collection time, the domain resolved to 188.114.97.3. Collected metadata identifies Dota 2 as the apparent target. Captured page title: “FIREROUNDS”. PhishDestroy classified the observed content as Brand Impersonation. DOM analysis completed on Apr 23, 2026 at 07:21 UTC; stored DOM score 25/100. IoC extraction completed on Aug 2, 2026 at 04:15 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis24/07/2026
firerounds.com was registered on 21 February 2026 through the REGRU‑RU registrar. The domain resolves to 188.114.97.3, an address owned by Cloudflare (AS13335) located in the United States. DNS is served by chan.ns.cloudflare.com and dexter.ns.cloudflare.com, indicating the use of Cloudflare’s managed name‑service. The page title returned from the last known capture is "FIREROUNDS", and the site currently returns an offline status with no TLS certificate, meaning any future traffic would be unencrypted. The domain has been classified as a brand‑impersonation campaign targeting the Dota 2 franchise.
Security‑grade services reflect extreme distrust: Gridinsoft assigns a score of 1 / 100, Scamadviser 31 / 100, and the domain appears on a single known blocklist. VirusTotal analysis shows 11 of 93 scanning engines flag the domain as malicious, and AlienVault OTX lists the domain in 14 separate threat‑intel pulses. PhishDestroy has also added the domain to its block list. Evidence suggests the operators are leveraging Cloudflare’s infrastructure to hide origin and benefit from the provider’s global edge network, a common tactic for short‑lived phishing sites. The lack of an SSL certificate may be intentional to avoid certificate‑pinning checks, or it could be a result of the site being taken down.
No further content or login page details are available, so the exact lure or credential‑harvesting method remains unknown. Defenders should continue to block 188.114.97.3 at the network perimeter and add firerounds.com to URL filtering policies. Monitoring of Cloudflare‑hosted domains for sudden appearance of new DNS records or changes in HTTP status is recommended. Incident response teams should treat any email or social‑media messages referencing "FIREROUNDS" or Dota 2‑related rewards with heightened scrutiny, as the domain has been actively used in brand‑impersonation campaigns.
مؤشرات الأمان
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
حصلت ICANN على أموالها. أما المساءلة فلم تصل.
بالنسبة إلى نطاق gTLD هذا، يعمل المسجّل المذكور أعلاه بموجب عقد مع ICANN. وتحصّل ICANN رسوماً سنوية ومتغيرة ورسومًا قائمة على المعاملات مرتبطة بعمليات التسجيل والتجديد والنقل.
الاعتماد: جرت الاستفادة منه مالياً. المساءلة: يُرجى التحقق مرة أخرى لاحقاً.
ثم يبدأ السحر: تكتب ICANN البند RAA §3.18، ويتولى المسجّل التحقيق في إساءة الاستخدام داخل قاعدة عملائه، ويقدّم الضحايا الأدلة مجاناً، بينما تنتظر كل طبقة أن يتحرك طرف آخر. إذا كان ذلك يجعل الضحايا يشعرون بمزيد من الأمان، فممتاز—لقد أدّت الفاتورة مهمتها.
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
حول هذا التقرير: firerounds.com
يقدم هذا التقرير أحدث الأدلة المخزنة المتاحة لـ PhishDestroy. يتم عرض الطوابع الزمنية للمصدر حيثما كان ذلك متاحًا؛ يمكن أن تتغير أحكام التوفر والبائعين بعد التجميع.
عرض الموقع الذي تم التقاطه عنوان الصفحة “FIREROUNDS” وربما ينتحل شخصية Dota 2.
اعتبارًا من 07/08/2026، كان لدى firerounds.com اكتشافات من محركات الأمان 11.
إذا كنت تعتقد أن هذه القائمة غير دقيقة، تقديم استئناف. للتعرف على منهجيتنا، قم بزيارة صفحة الأسئلة الشائعة.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب