الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 16. قوائم الحظر العامة التي تبلغ عن تطابق: 3. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

galixwallet[.]co[.]com

“Holdexer - Secure Hardware Wallet for Cryptocurrency”

حكم التهديد حرجة 100/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 16/93 Spamhaus DBL: DBL_PHISH تطابقات القائمة السوداء المخزنة: 3 نوع الاحتيال: Seed Phrase Theft
21/12/2025

ملاحظة محفوظة

تباين العناوين المرصود

العنوان المعروض للماسحYahoo
العنوان المعروض للزائرHoldexer - Secure Hardware Wallet for Cryptocurrency

ملخص الأدلة

حرج
Evidence score
100/100

This domain, galixwallet.co.com, is assessed as a high-risk crypto seed drainer phishing site. Infrastructure analysis reveals it was registered via Moniker Online Services LLC on August 16, 1997, an unusually early date that may indicate domain recycling or falsified registration details. The domain currently resolves to IP 212.118.38.157, hosted on AS216071 (SERVERS TECH FZCO) in the Netherlands, a network frequently associated with malicious activity. Nameservers are split between regway.com and nic.co.com, a pattern often seen in bulletproof or low-reputation hosting setups. The site presents itself under the page title 'Holdexer - Secure Hardware Wallet for Cryptocurrency', suggesting a targeted impersonation of hardware wallet services to harvest seed phrases.

This aligns with the classified scam type: Wallet/Seed Phishing, specifically employing a Seed Phrase Phishing kit. No direct brand impersonation is confirmed beyond the page title, and the exact visual or functional mimicry is not analysed. Detection evidence is substantial: the domain appears on four security blocklists and is actively blocked by PhishDestroy, Polkadot, Enkrypt, and Codeesura, indicating cross-industry recognition of the threat. Gridinsoft and Scamadviser both assign trust scores of 1 or lower out of 100, reinforcing the high-risk classification. The SSL certificate, issued by DigiCert Inc (Global G2 TLS RSA SHA256 2020 CA1), is valid but does not mitigate the malicious intent, as phishing sites commonly use legitimate certificates to appear trustworthy.

As of July 25, 2026, the domain is offline with an HTTP 404 status, though this does not confirm permanent takedown. Defenders should treat all prior resolutions of this domain as compromised infrastructure. Recommended actions include blocking the domain and IP at perimeter controls, monitoring for re-emergence under the same or similar names, and alerting users who may have interacted with the site before it was taken offline.

VirusTotal
VirusTotal
16 det.
DNS Security
7/14
رادار CF
ضار
شهادة TLS
DigiCert SHA2 High Assurance Server CA
العمر
29 yr
الحالة المرصودة
المحتوى غير متوفر HTTP 404
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 16 / 93 URLQuery تم تخزين التقرير - الحكم التفصيلي معلق PhishStats checked — no match recorded OTX no community references رادار CF provider verdict: malicious URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 7/14 TLS valid certificate, 32d WHOIS 353 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
مؤشرات الأمان
SA Scamadviser Warnings
The owner of the website is using a service to hide their identity on WHOIS According to Tranco this site has a low rank The registrar has a high % of spammers and fraud sites This website is (very) young. We tried to analyze the content of the site but failed This website seems to offer financial services but does not have a valid SSL certificate This website has been reported for Phishing by IPQS This website has been reported as Suspicious by IPQS
استخبارات أمن الشبكات
DNS Provider Blocks 7 / 14
Adguard Default Adguard Family Cloudflare Family Cloudflare Security Controld Adblock Controld Family Controld Malware
CF Cloudflare Radar Verdict ضار
Phishing Security threats Phishing

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
14/15

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026

٧ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. Cloudflare Radar

    تم حفظ فحص Cloudflare Radar · فتح الفحص

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN nginx/1.28.0 · AS216071 VDSINA SERVERS TECH FZCO, AE
سمعة عنوان IP IP abuse confidence 0/100 0 reports checked 28/07/2026
مزود المنصة Moniker Online Services US(US)
جهة الإبلاغ عن إساءة الاستخدامabuse@vdsina.com, abuse@moniker.com
عنوان IP 212.118.38.157 NL
الموقع الجغرافيNL Amsterdam, NL
الشبكةAS216071 · SERVERS TECH FZCO
حالة HTTP404 Not Found
الوقت حتى أول تعذّر للوصول 84 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف21/12/2025
DOM Analysisanalyzed 11/03/2026DOM analysis score 70/100
Submitted URLhttp://galixwallet.co.com/
خوادم الأسماءdns1.regway.comdns2.regway.comdns3.regway.comdns4.regway.comns1.nic.co.comns2.nic.co.comns3.nic.co.comns4.nic.co.com
بصمة TLS
رصد TLSصالح منذ 03/03/2026فُحص في 12/03/2026
الأسماء البديلة لموضوع TLSadd.my.yahoo.combrb.yahoo.netca.my.yahoo.comca.rogers.yahoo.comddl.fp.yahoo.comfr-ca.rogers.yahoo.comhk.rd.yahoo.commbp.yimg.coms.yimg.comtw.rd.yahoo.comyahoo.com
عنوان الصفحة
Holdexer - Secure Hardware Wallet for Cryptocurrency
شهادة TLS
Valid transport encryption · صادرة عن DigiCert SHA2 High Assurance Server CA · valid for 32 days
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

16 / قام موردو الأمان 93 بوضع علامة على هذا المجال
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
BitDefender
CRDF
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
Phishing Database
سوفوس
Trustwave
VIPRE
Webroot
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of galixwallet.co.com · checked Mar 2, 2026

100
Good
Performance
FCP
0.78s
First Contentful Paint
LCP
0.78s
Largest Contentful Paint
CLS
0.008
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
1.25s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

ScamAdviserScamAdviser درجة الثقة 1/100الحالة: Very Likely Unsafeفتح المصدر
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/galixwallet.co.com"
  title="PhishDestroy threat report for galixwallet.co.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>