الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 25. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

galaticothaikhongg[.]netlify[.]app

“Facebook”

حكم التهديد حرجة 100/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 25/92 URLQuery threat systems: 4 alerts انتحال العلامة التجارية: Facebook
15/05/2026 Facebook CDN

ملخص الأدلة

حرج
Evidence score
100/100

PhishDestroy identifies galaticothaikhongg.netlify.app as an active high-risk phishing domain hosting a cryptocurrency drainer kit designed to steal wallet credentials and funds. This fraudulent site impersonates a legitimate service to deceive users into connecting their wallets, triggering unauthorized transactions. The domain leverages Netlify’s hosting infrastructure to evade traditional detection mechanisms while distributing malicious JavaScript payloads capable of draining crypto assets without user consent. The threat actor behind this campaign employs social engineering tactics, including fake login prompts and wallet connection requests, to trick victims into authorizing transactions that transfer funds to attacker-controlled addresses. This domain was flagged by PhishDestroy with a high-risk classification due to its active exploitation in the wild. Technical indicators include a VirusTotal detection rate of 11/95 security vendors, a Netlify registration, and resolution to IP address 63.176.8.218. Google Safe Browsing has classified this domain under SOCIAL_ENGINEERING, and it remains unblocked by most major threat intelligence platforms. The domain’s SSL certificate, issued by DigiCert Inc, adds a false sense of legitimacy, further increasing the risk of successful deception. Given the lack of widespread blocking and the domain’s recent activity, the window for exposure remains significant. As of the latest assessment, galaticothaikhongg.netlify.app remains an active threat with no signs of takedown. Users are strongly advised to avoid interacting with this domain and report it immediately via PhishDestroy’s threat intelligence portal. The remaining risk is classified as high due to the domain’s evasion of standard detection mechanisms and its potential to cause irreversible financial loss. Immediate action, including network-level blocking and user awareness campaigns, is recommended to mitigate further exposure. PhishDestroy continues to monitor this domain and will update its threat intelligence feed as new developments arise.

VirusTotal
VirusTotal
25 det.
URLQuery
URLQuery
4 threat alerts
DNS Security
6/14
رادار CF
ضار
شهادة TLS
DigiCert Inc
Hosting
Netlify
العمر
3 mo New
الحالة المرصودة
المحتوى غير متوفر HTTP 503
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 25 / 92 URLQuery 4 threat-system alerts PhishStats checked — no match recorded OTX no community references رادار CF provider verdict: malicious URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS 6/14 TLS valid certificate, 308d WHOIS 3 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
DNS Provider Blocks 6 / 14
Brand Gala Cloudflare Family Cloudflare Security Controld Adblock Controld Family Controld Malware
Threat Detection Systems 4 alerts
Detection System Indicator Verdict Alert
Cloudflare DNS galaticothaikhongg.netlify.app malicious Sinkholed
OpenDNS galaticothaikhongg.netlify.app phishing Phishing Block
DNS4EU galaticothaikhongg.netlify.app malicious Sinkholed
Quad9 DNS galaticothaikhongg.netlify.app malicious Sinkholed
CF Cloudflare Radar Verdict ضار
Phishing Phishing Security threats
Free Hosting Detected Netlify
This domain is hosted on Netlify (free hosting platform). Free hosting platforms are commonly used for both legitimate testing/development and malicious purposes. Additional context is needed for a de

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
15/16

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: Facebook report ↗
Google Safe Browsing تم وضع علامة عليها Social engineering checked 15/05/2026
الخادم / ASN Netlify · AS16509 Amazon.com, Inc.
IP Context Netlify shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مزود المنصة Netlify US(US)
جهة الإبلاغ عن إساءة الاستخدامabuse@netlify.com
عنوان IP 63.176.8.218 CDN
الموقع الجغرافيDE Frankfurt am Main, DE
الشبكةAS16509 · AWS EC2 (eu-central-1)
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
حالة HTTP503 Error
الوقت حتى أول تعذّر للوصول 55 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف15/05/2026
Submitted URLhttp://galaticothaikhongg.netlify.app/
بصمة TLS
رصد TLSصالح منذ 16/02/2026فُحص في 15/05/2026
الأسماء البديلة لموضوع TLSnetlify.app
عنوان الصفحة
Facebook
شهادة TLS
Valid transport encryption · صادرة عن DigiCert Inc · valid for 308 days

التقنيات

حُدّدَت تقنيتان عاليتا الثقة

Netlify HSTS
Cloudflare Radar
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

25 / قام موردو الأمان 92 بوضع علامة على هذا المجال
View on VT
Last analyzed
ADMINUSLabs
Criminal IP
alphaMountain.ai
BitDefender
Ermes
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Google Safebrowsing
Gridinsoft
كاسبرسكي
LevelBlue
Lionic
MalwareURL
Mimecast
نتكرافت
OpenPhish
PREBYTES
Seclookup
سوفوس
URLQuery
VIPRE
Webroot
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of galaticothaikhongg.netlify.app · checked May 15, 2026

100
Good
Performance
FCP
0.93s
First Contentful Paint
LCP
1.84s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
0.95s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/galaticothaikhongg.netlify.app"
  title="PhishDestroy threat report for galaticothaikhongg.netlify.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>