gu[.]exchanges[.]asia
فحص التصيد والأمان للنطاق gu.exchanges.asia
“Gu Factory”
gu.exchanges.asia — خطأ في الخادم (HTTP 502). انتحال العلامة التجارية: Arbitrum; نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 2/93 (G-Data, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 71/100. مسجّل النطاق: Web Commerce Communica….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain gu.exchanges.asia was registered on 21 February 2026 through Web Commerce Communications Limited dba WebNic.cc and is served from the IP address 104.21.80.1, which belongs to AS13335 Cloudflare, Inc. in the United States. The site presented a page titled “Gu Factory” and was classified as a wallet/seed phishing operation targeting users of the Arbitrum blockchain platform. SSL analysis shows the site used a Cloudflare TLS Issuing ECC CA 1 certificate, indicating standard Cloudflare TLS termination.
Reputation scoring from Gridinsoft assigned a trust score of 0 out of 100, reflecting extreme suspicion. The domain appears on two independent security blocklists—PhishDestroy and ScamSniffer—and has been flagged by two of ninety‑three VirusTotal security vendors, reinforcing its malicious reputation. Nameserver records point to ns100.webnic.cc and ns101.webnic.cc, consistent with the registrar’s infrastructure.
Current operational status is offline, limiting direct observation of the payload, but the combination of low trust score, blocklist listings, SSL provider, and the wallet/seed phishing label provides sufficient evidence for remediation. Defenders should block DNS resolution for gu.exchanges.asia, deny traffic to its hosting IP 104.21.80.1, and monitor for any related infrastructure that may reuse the same Cloudflare ASN or WebNic nameservers. Continuous threat‑intel feeds should be consulted for any re‑appearance of the domain or associated indicators of compromise.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: exchanges.asia
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain exchanges.asia behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب