الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 5. قوائم الحظر العامة التي تبلغ عن تطابق: 1. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

gokabuto[.]org

“Kabuto | Airdrop”

حكم التهديد حرجة 80/100 درجة الأدلة
التوفر آخر نشاط معروف أحدث مراقبة إمكانية الوصول المخزنة
اكتشافات VirusTotal: 5/95 تطابقات القائمة السوداء المخزنة: 1 نوع الاحتيال: Crypto Scam آخر نشاط معروف
OTX: 23 refs 03/12/2025 CDN

ملخص الأدلة

حرج
Evidence score
80/100

Analysis indicates that gokabuto.org is currently active and hosted behind Cloudflare's network (AS13335) with the IP 172.67.181.75 located in the United States. The domain was registered on 2025-12-02 through Cloudflare and uses the Google Trust Services / WE1 certificate. DNS is served by darl.ns.cloudflare.com and laura.ns.cloudflare.com. HTTP requests return a 200 status and the page title reports "Kabuto | Airdrop", consistent with the identified phishing kit labeled "Airdrop Scam" and the broader classification of a crypto-related scam. VirusTotal records five detections out of ninety-five scanners, and the domain appears on two public blocklists; it has also been flagged by PhishDestroy and ScamSniffer. AlienVault OTX cites the domain in twenty-three threat-intel pulses, confirming its inclusion in multiple observables. Technologies observed include jsDelivr, Cloudflare and HTTP/3, suggesting typical content-delivery infrastructure rather than bespoke malicious code. The Gridinsoft trust score of 0/100 reinforces the malicious rating. While the exact content of the landing page has not been inspected, the combination of the airdrop-themed title, crypto-scam kit, and multiple vendor detections provides strong evidence of a phishing operation targeting cryptocurrency users. Defenders should block and monitor traffic to gokabuto.org, add the IP and associated hostnames to deny-list rules, and continue to watch for any related C2 infrastructure that may share the same Cloudflare edge. Ongoing collection of URL snapshots and sandbox analysis is recommended to confirm payload behavior and to update detection signatures.

VirusTotal
VirusTotal
5 det.
OTX references
شهادة TLS
Google Trust Services
العمر
8 mo
الحالة المرصودة
آخر نشاط معروف HTTP 200
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 5 / 95 URLQuery تم تخزين التقرير - الحكم التفصيلي معلق PhishStats لم يتم التحقق منها OTX 23 community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 44d WHOIS 8 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
11/13

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026

٩ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. VirusTotal

    2 ← 3

  2. VirusTotal

    2 ← 5

لقطة محفوظة

عنوان الصفحة
Kabuto | Airdrop
شهادة TLS
Valid transport encryption · صادرة عن Google Trust Services · valid for 44 days

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN cloudflare · AS13335 CLOUDFLARENET, US
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق Cloudflare US(US)
جهة الإبلاغ عن إساءة الاستخدامabuse@gokabuto.org
البحث في قاعدة بيانات WHOISICANN RDAP لـ gokabuto.org →
عنوان IP 172.67.181.75 CDN
الموقع الجغرافيUS San Francisco, US
الشبكةAS13335 · Cloudflare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 02/12/2025 (251d)
Elapsed Since First Report 103 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: آخر نشاط معروف.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
حالة HTTP200
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف03/12/2025
DOM Analysisanalyzed 11/03/2026DOM analysis score 10/100
Submitted URLhttps://gokabuto.org/
خوادم الأسماءdarl.ns.cloudflare.comlaura.ns.cloudflare.com
بصمة TLS
رصد TLSصالح منذ 30/01/2026فُحص في 11/03/2026
Favicon Hash
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

5 / قام موردو الأمان 95 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 2 detections
alphaMountain.ai
Chong Lua Dao
CRDF
Forcepoint ThreatSeeker
Gridinsoft
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of gokabuto.org · checked Jul 12, 2026

54
Needs Work
Performance
FCP
1.7s
First Contentful Paint
LCP
10.32s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
616ms
Total Blocking Time
SI
5.48s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/gokabuto.org"
  title="PhishDestroy threat report for gokabuto.org"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.