gass-hemat138[.]pages[.]dev
“HEMAT138 | Slot Thailand Slot88 yang Lagi Ramai Diburu”
ملخص الأدلة
This domain, gass-hemat138.pages.dev, is currently under investigation for hosting a slot-themed credential phishing scheme targeting users in Southeast Asia. The site presents itself as a gambling platform, specifically promoting "Slot Thailand Slot88 yang Lagi Ramai Diburu," a phrase commonly associated with fraudulent online slot services. These platforms often mimic legitimate gaming sites to harvest login credentials, financial details, or install malware under the guise of offering high-stakes gambling opportunities. Users who engage with such sites risk unauthorized access to personal accounts, financial loss, or device compromise through malicious payloads delivered via fake game clients or embedded scripts. Analysis indicates the domain was registered on May 19, 2026, through Cloudflare, Inc., and is hosted on infrastructure resolving to the IP address 172.66.46.230. The SSL certificate is issued by Let’s Encrypt, a common practice among threat actors to lend an appearance of legitimacy. Despite its recent creation, the domain has not yet been widely detected by security vendors, with a VirusTotal score of 0 out of 95 engines flagging it as malicious. However, it appears on one security blocklist, PhishDestroy, suggesting preliminary identification of phishing characteristics. The use of Cloudflare’s content delivery network further complicates attribution, as it obscures the true origin of the malicious content and may delay takedown efforts. Users who have visited gass-hemat138.pages.dev or interacted with its content should take immediate action to mitigate potential risks. First, disconnect the device from the network to prevent further data exfiltration or command-and-control communication. Run a full scan using updated antivirus software to detect any installed malware or unauthorized scripts. If credentials were entered, change passwords for all associated accounts, prioritizing financial services, email, and social media platforms. Enable multi-factor authentication where available to add an additional layer of security. Monitor bank statements and transaction histories for unauthorized activity, and report any suspicious findings to the relevant financial institution. Finally, consider reporting the domain to local cybersecurity authorities or platforms like the Anti-Phishing Working Group to aid in broader mitigation efforts.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
التقنيات
حُدّدت ٥ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of gass-hemat138.pages.dev · checked May 19, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب