الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref 43D03F14

MALICIOUS — CRITICAL

ggderop[.]com

This domain, ggderop.com, is flagged as a fake login portal designed to harvest user credentials.

72/100 evidence score · Critical
VirusTotal
6/94
Blocklists
No stored match
التوفر
المحتوى غير متوفر · HTTP 502
Report / Add Evidence Appeal this listing
2026-03-27 20:49 UTCالمحتوى غير متوفر · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 6. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
Jump to section
ملخص التقرير

ggderop.com — المحتوى غير متوفر (HTTP 502). ملخص الأدلة: VirusTotal 6/94 (alphaMountain.ai, Chong Lua Dao, CRDF, Gridinsoft, SOCRadar); URLQuery 2 alerts; PhishDestroy score 72/100. مسجّل النطاق: NiceNIC.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref 43D03F14

This domain, ggderop.com, is flagged as a fake login portal designed to harvest user credentials. Analysis indicates no direct association with a specific brand or drainer kit, but the infrastructure aligns with generic phishing campaigns targeting login credentials for financial or corporate services. The domain lacks overt branding, suggesting a broad, opportunistic attack vector rather than a targeted impersonation effort.

Infrastructure analysis reveals the following technical indicators: VirusTotal detection score of 6/95 security vendors, indicating moderate confidence in malicious classification. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 27, 2026, with a suspiciously future-dated creation timestamp, a common tactic to evade immediate detection. It resolves to IP address 104.21.83.229, a Cloudflare-associated endpoint frequently leveraged to obscure hosting origins. The domain appears on one security blocklist and was previously blocked by internal filtering systems. Google Safe Browsing (GSB) status is not explicitly provided, but the VirusTotal score and blocklist presence corroborate its malicious nature.

Current status indicates the domain has been taken offline, likely due to enforcement actions or hosting provider intervention. However, residual risk persists due to the domain's registration remaining active until 2026, allowing potential reactivation. Response actions should include monitoring for DNS reactivation, blocking the resolved IP (104.21.83.229) at the network perimeter, and alerting users to credential exposure risks. Organizations are advised to review logs for connections to this domain or IP and rotate credentials if interaction is detected. The registrar, NICENIC INTERNATIONAL GROUP CO., LIMITED, has been linked to other malicious registrations, warranting heightened scrutiny of domains registered through this entity.

VirusTotal
VirusTotal
6 det.
URLQuery
URLQuery
2 threat alerts
شهادة TLS
منتهية الصلاحية أو غير متحقق منها
العمر
4 mo
الحالة المرصودة
المحتوى غير متوفر 502
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات12 recorded checks
VirusTotal 6 / 94 URLQuery 2 threat-system alerts PhishStats لم يتم التحقق منها OTX not queried رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 4 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات Registrar context
Threat Detection Systems 2 alerts
Detection System Indicator Verdict Alert
OpenDNS ggderop.com phishing Phishing Block
DNS4EU ggderop.com malicious Sinkholed
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer:

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
14/14

حالة قوائم الحظر العامة

لقطة محفوظة

عنوان الصفحة
Эксклюзивные цифровые коллекции для настоящих ценителей!
شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن Google Trust Services / WE1

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق NiceNIC RU(RU) PhishDestroy Investigation
عنوان IP 104.21.83.229 CDN
الموقع الجغرافيCA Toronto, CA
الشبكةAS13335 · Cloudflare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 27/03/2026 (134d)
حالة HTTP502 Error
الوقت حتى أول تعذّر للوصول 131 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف27/03/2026
DOM Analysisanalyzed 29/07/2026score 15/100
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
خوادم الأسماءrandy.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 10/03/2026scanned 28/03/2026
Case ID
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.

Latest Classified Outcome 2026-08-09 03:55:30 UTC

Primary outcome Inactive reason: Not registered in RDAP 90% confidence
Attribution mechanism: Rdap 404 source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Not registered
Latest HTTP observation غير معروف Origin unreachable Http 5xx 20% 2026-08-09 01:35:14 UTC
RDAP registration Not registered RDAP HTTP 404 source: Rdap Status Collector checked 2026-08-09 03:55:30 UTC
Observed timeline last reachable: 2026-03-31 06:31:04 UTC current episode first observed: 2026-08-05 01:45:38 UTC observed RIP window: 2026-03-31 06:31:04 UTC → 2026-08-05 01:45:38 UTC · 3,043.24h midpoint estimate ≈ 2026-06-02 16:08:21 UTC · precision very low · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

6 / قام موردو الأمان 94 بوضع علامة على هذا المجال
View on VT
Last analyzed
alphaMountain.ai
Chong Lua Dao
CRDF
Gridinsoft
SOCRadar
سوفوس
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of ggderop.com · checked Jun 26, 2026

69
Needs Work
Performance
FCP
3.46s
First Contentful Paint
LCP
7.14s
Largest Contentful Paint
CLS
0.002
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
3.46s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260327-9962FC Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org
Page title stored with report: Эксклюзивные цифровые коллекции для настоящих ценителей!
نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/ggderop.com"
  title="PhishDestroy threat report for ggderop.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.