الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 6. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

gro90p-fxempire[.]com

حكم التهديد حرجة 72/100 درجة الأدلة
التوفر خطأ في الخادم آخر استجابة مخزنة كانت غير حاسمة
اكتشافات VirusTotal: 6/94 Spamhaus DBL: DBL_PHISH URLQuery threat systems: 2 alerts نوع الاحتيال: Fake Exchange
02/04/2026 1 Report Sent CDN

ملخص الأدلة

حرج
Evidence score
72/100

PhishDestroy identifies gro90p-fxempire.com as a high-risk crypto drainer domain currently active in phishing campaigns targeting cryptocurrency users. This domain mimics legitimate financial platforms to trick victims into connecting wallets and signing malicious transactions that drain digital assets. Security researchers have observed similar domains exploiting brand impersonation tactics, leveraging urgency and financial incentives to bypass user skepticism. The domain’s infrastructure is designed to facilitate unauthorized cryptocurrency transfers once victims engage with embedded drainer scripts, making it a critical threat to digital asset holders. This domain was flagged with 6 out of 95 VirusTotal detections, indicating it has evaded initial automated detection systems despite its malicious intent. Registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 28, 2026, the domain resolves to IP address 188.114.97.3 and holds a valid Let’s Encrypt SSL certificate, which may lend false credibility to unsuspecting users. The combination of a newly registered domain, low detection rates, and active infrastructure suggests this may be part of a larger, evolving phishing campaign targeting crypto investors. Users who visited gro90p-fxempire.com should immediately disconnect any connected cryptocurrency wallets and revoke any permissions granted to unknown domains or applications. Scan devices for malware using reputable antivirus tools and monitor wallet transactions for unauthorized activity. Report the domain to your security team or relevant cybercrime authorities to aid in takedown efforts. Avoid interacting with any prompts or transactions on this site, as it is actively engaged in crypto drainer operations.

لقطة الأدلة المرسلة

أُرسل
سجلات الدفتر
1
معرّف القضية
PD-20260402-C7F22F
عنوان الصفحة الملتقطة
Just a moment...
ملف PDF
دليل PDF
النص الكامل للدليل
Registrar: NICENIC International Group Co., Limited (Hong Kong (China))
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
VirusTotal
VirusTotal
6 det.
URLQuery
URLQuery
2 threat alerts
شهادة TLS
Let's Encrypt
العمر
4 mo
الحالة المرصودة
خطأ في الخادم HTTP 502
PhishDestroy
قائمة الإتلاف
مدرج
Reports Sent
1

Data Coverage

VirusTotal 6 / 94 URLQuery 2 threat-system alerts PhishStats checked — no match recorded OTX no community references رادار CF no data URLScan capture التقرير المخزن URLScan verdict التقييم غير متاح حجب عناوين DNS 12 تم الفحص — لا يوجد حظر TLS valid certificate, 84d WHOIS 4 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكاتRegistrar context
Threat Detection Systems 2 alerts
Detection System Indicator Verdict Alert
DNS4EU gro90p-fxempire.com malicious Sinkholed
OpenDNS gro90p-fxempire.com phishing Phishing Block
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
10/11

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

أدلة النتيجة المحفوظة

النتيجة وإسناد الإزالة

النتيجة
held
التوفر
unreachable
السبب
registrar_client_hold
الجهة الفاعلة
NICENIC INTERNATIONAL GROUP CO., LIMITED
الآلية
client_hold
درجة الثقة
95%
أول رصد
أحدث رصد

وقت التعطل التقديري

الوقت حتى تعذر الوصول: 0 h

SHA-256 للدليل c7de867480f7

المخطط الزمني للاكتشاف

  1. التوفر

    أول قيمة محفوظة: DNS غير نشط

    f93a11f87e4d
  2. التوفر

    DNS غير نشط ← غير معروف

    b901fe6383e9
  3. التوفر

    غير معروف ← DNS غير نشط

    c300c59df119
  4. التوفر

    DNS غير نشط ← محتجز

    6bdeb3feb132
  5. التوفر

    محتجز ← DNS غير نشط

    f52d526b76a1
  6. التوفر

    DNS غير نشط ← غير معروف

    d437d22544cc
  7. التوفر

    غير معروف ← محتجز

    eb99e1d51216
  8. التوفر

    محتجز ← غير معروف

    eaad31c1598d
  9. التوفر

    غير معروف ← DNS غير نشط

    6dfe9145995c
  10. التوفر

    DNS غير نشط ← محتجز

    9f059a64ff66
عرض الكل (15)
  1. التوفر

    محتجز ← DNS غير نشط

    641ed81dc4d5
  2. التوفر

    DNS غير نشط ← غير معروف

    e5fb11d44bf4
  3. التوفر

    غير معروف ← محتجز

    316e5a9e5cf2
  4. التوفر

    محتجز ← غير معروف

    2a934ef31fea
  5. التوفر

    غير معروف ← DNS غير نشط

    d0b7046e8c2f
  6. التوفر

    DNS غير نشط ← محتجز

    4bb9679f3f13
  7. التوفر

    محتجز ← DNS غير نشط

    ca9ed662b468
  8. التوفر

    DNS غير نشط ← غير معروف

    888fe5959ccb
  9. التوفر

    غير معروف ← محتجز

    6bdfdcf248ef
  10. التوفر

    محتجز ← DNS غير نشط

    92f667ff6e00
  11. التوفر

    DNS غير نشط ← غير معروف

    fe8060059f27
  12. التوفر

    غير معروف ← محتجز

    c2de9e0fc65b
  13. التوفر

    محتجز ← DNS غير نشط

    9eda8dc3b7e8
  14. التوفر

    DNS غير نشط ← غير معروف

    b4c717aac11a
  15. التوفر

    غير معروف ← محتجز

    c7de867480f7

بلاغات المجتمع

أبلغ عنه عضو واحد في المجتمع؛ شوهد أول مرة في 02/04/2026

البلاغات المحفوظة
1
عناوين URL الفريدة المبلغ عنها
1
مقبول1

لقطة محفوظة

شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 84 days

معلومات النطاق

النطاق
الخادم / ASN AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق NiceNIC RU(RU) PhishDestroy Investigation
جهة الإبلاغ عن إساءة الاستخدامabuse@nicenic.net
البحث في قاعدة بيانات WHOISICANN RDAP لـ gro90p-fxempire.com →
عنوان IP 188.114.97.3 CDN
الموقع الجغرافيCA Toronto, CA
الشبكةAS13335 · CloudFlare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 02/04/2026 (132d)
حالة HTTP502 Error
Elapsed Since First Report 20 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: خطأ في الخادم.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف02/04/2026
DOM Analysisanalyzed 29/07/2026DOM analysis score 63/100
Submitted URLhttps://gro90p-fxempire.com/
خوادم الأسماءzeus.ns.cloudflare.com
رصد TLSفُحص في 23/05/2026
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

6 / قام موردو الأمان 94 بوضع علامة على هذا المجال
View on VT
Last analyzed
alphaMountain.ai
CyRadar
Fortinet
G-Data
Gridinsoft
سوفوس
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of gro90p-fxempire.com · checked Apr 2, 2026

68
Needs Work
Performance
FCP
2.88s
First Contentful Paint
LCP
30.38s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
157ms
Total Blocking Time
SI
2.97s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/gro90p-fxempire.com"
  title="PhishDestroy threat report for gro90p-fxempire.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.