florewards[.]xyz
ملخص الأدلة
This report analyzes the domain florewards.xyz, which was hosting a fake airdrop scam. The site presented a page titled "Just a moment..." and impersonated a legitimate cryptocurrency airdrop campaign to deceive users. The threat posed by this site involves credential theft or wallet compromise, as victims are tricked into providing sensitive information or connecting their wallets under the guise of claiming a fraudulent airdrop.
Technical analysis reveals the site was flagged by 4 out of 95 VirusTotal vendors, specifically Fortinet, Gridinsoft, Seclookup, and SOCRadar. The domain appears on 1 blocklist. It is registered with NiceNIC International Group Co., Limited and was created on 2026-02-21. The IP address 188.114.96.3 is located in the United States and is associated with AS13335 Cloudflare, Inc. The site uses an SSL certificate issued by Google Trust Services / WE1, with nameservers dylan.ns.cloudflare.com and selah.ns.cloudflare.com.
As of the time of analysis, florewards.xyz is currently offline. The risk level is assessed as high due to the site's clear scam nature, recent creation date, and the specific threat of financial loss through fake airdrop schemes. Users should avoid any interaction with this domain or similar content.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260214-8690D4- عنوان الصفحة الملتقطة
- Just a moment...
- ملف PDF
- دليل PDF
النص الكامل للدليل
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | florewards.xyz |
malicious | Sinkholed |
| Quad9 DNS | florewards.xyz |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
أدلة النتيجة المحفوظة
النتيجة وإسناد الإزالة
- النتيجة
held- التوفر
unreachable- السبب
registry_server_hold- الآلية
server_hold- درجة الثقة
- 95%
- أول رصد
- أحدث رصد
وقت التعطل التقديري
الوقت حتى تعذر الوصول: 0 hSHA-256 للدليل f3f9dc41b6bf
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
-
التوفر
أول قيمة محفوظة: DNS غير نشط
f93a11f87e4d -
التوفر
DNS غير نشط ← غير معروف
4299cb3ddd0c -
التوفر
غير معروف ← غير نشط
7c64089370a2 -
التوفر
غير نشط ← DNS غير نشط
073f6e0aa648 -
التوفر
DNS غير نشط ← محتجز
67de09ac448d -
التوفر
محتجز ← DNS غير نشط
f52d526b76a1 -
التوفر
DNS غير نشط ← غير معروف
f759de07dcba
عرض الكل (19)
-
التوفر
غير معروف ← محتجز
fbe24d89b566 -
التوفر
محتجز ← غير معروف
664b60f6ea36 -
التوفر
غير معروف ← DNS غير نشط
6dfe9145995c -
التوفر
DNS غير نشط ← محتجز
831a09f61e23 -
التوفر
محتجز ← DNS غير نشط
641ed81dc4d5 -
التوفر
DNS غير نشط ← غير معروف
6c1a40af8723 -
التوفر
غير معروف ← محتجز
d22a956edb09 -
التوفر
محتجز ← غير معروف
5df7e338b8da -
التوفر
غير معروف ← DNS غير نشط
d0b7046e8c2f -
التوفر
DNS غير نشط ← محتجز
b31e0267196c -
التوفر
محتجز ← DNS غير نشط
ca9ed662b468 -
التوفر
DNS غير نشط ← غير معروف
f0d714569cb1 -
التوفر
غير معروف ← محتجز
2e5f1116ff7b -
التوفر
محتجز ← DNS غير نشط
92f667ff6e00 -
التوفر
DNS غير نشط ← غير معروف
22369edad508 -
التوفر
غير معروف ← محتجز
95bb8a94418b -
التوفر
محتجز ← DNS غير نشط
9eda8dc3b7e8 -
التوفر
DNS غير نشط ← غير معروف
096462495a72 -
التوفر
غير معروف ← محتجز
f3f9dc41b6bf
بلاغات المجتمع
أبلغ عنه عضو واحد في المجتمع؛ شوهد أول مرة في 12/02/2026
- البلاغات المحفوظة
- 1
- عناوين URL الفريدة المبلغ عنها
- 1
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب