getipass[.]refur-trw[.]cc
“404 Not Found”
ملخص الأدلة
The domain getipass.refur-trw.cc was registered on June 12, 2026 through Dominet (HK) Limited and is currently active. DNS resolution points to the IPv4 address 188.114.96.3, and the authoritative name servers are osmar.ns.cloudflare.com and ulla.ns.cloudflare.com, indicating the use of Cloudflare’s DNS infrastructure. Threat intelligence platforms have recorded the domain on a single security blocklist, and it is actively blocked by the PhishDestroy mitigation service.
VirusTotal analysis shows that ten out of ninety‑one scanned security vendors have flagged the domain as malicious, providing a modest but notable detection ratio that reinforces the suspicion of phishing activity. No additional data such as SSL certificate details, HTTP response codes, or page titles have been published, leaving those aspects of the site’s behavior unverified at this time. The limited but consistent evidence—registration timing, Cloudflare name server usage, presence on a blocklist, active blocking by PhishDestroy, and multiple vendor detections—supports a high confidence assessment that the domain is being used for generic phishing.
Defensive operators should prioritize the inclusion of getipass.refur-trw.cc in network and endpoint blocklists, monitor the associated IP address 188.114.96.3 for any anomalous traffic, and consider sinkholing or null‑routing the domain to disrupt its infrastructure. Continuous re‑evaluation is advised as additional telemetry, such as URL payloads or HTTP headers, becomes available.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
حالة النطاق
يتعذر الوصول إليه ← يمكن الوصول إليه
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
التقنيات
حُدّدَت تقنيتان عاليتا الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of getipass.refur-trw.cc · checked Jul 29, 2026
تحليل إعدادات الموقع
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب