gtasamods[.]com
“Download GTA San Andreas Mod Apk | Unlimited All”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
On 25 July 2026 analysts observed that the domain gtasamods.com is actively serving content under the page title “Download GTA San Andreas Mod Apk | Unlimited All”. The site resolves to the IPv4 address 188.114.96.3, which is assigned to AS13335 (Cloudflare, Inc.) and is geographically mapped to the United States. DNS resolution uses the Cloudflare authoritative name servers “maisie.ns.cloudflare.com” and “nash.ns.cloudflare.com”, and the HTTP response returns status code 200. The server negotiates HTTP/3, indicating modern transport support. The TLS certificate is issued by Google Trust Services under the “WE1” designation, providing a valid chain to a trusted root.
Registration information shows the domain was created on 21 February 2026 through the registrar Dynadot LLC. The domain is classified as a brand‑impersonation campaign targeting the “across” brand, as indicated in the supplied intelligence. Reputation checks reveal that PhishDestroy, MetaMask, and SEAL have added the domain to their blocklists, and three additional public blocklists also contain the address. VirusTotal analysis reports that four of ninety‑three scanning engines flagged the domain, confirming a modest level of malicious detection. Despite these indicators, the site remains reachable and continues to deliver HTTP 200 responses. Uncertainty remains regarding the exact malicious payload delivered, the extent of victim interaction, and whether any command‑and‑control infrastructure is associated with the host.
No detailed payload or dropper information was captured, and no public threat‑intel signatures beyond the blocklist entries have been published. Defenders should prioritize immediate DNS and URL filtering for gtasamods.com across enterprise perimeter defenses. Network monitoring should include alerts for outbound connections to 188.114.96.3 and any TLS handshakes using the Google Trust Services certificate observed on this host.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات
حُدّدَت تقنيتان عاليتا الثقة
تحليل VirusTotal
تحليل إعدادات الموقع
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب