heleket-invoice[.]com
“Heleket Pay”
ملخص الأدلة
The domain heleket-invoice.com is currently under investigation for generic phishing activity targeting payment processing systems. Analysis indicates the site impersonates a payment portal under the name 'Heleket Pay,' though no legitimate service by this name is known. The domain is presently offline, but prior activity suggests it was designed to harvest financial credentials or distribute fraudulent payment requests. Infrastructure analysis reveals the domain was registered through Global Domain Group LLC and resolves to the IP address 188.114.96.3. Despite its recent creation date of May 04, 2026, the domain has not been flagged by any of the 95 vendors on VirusTotal, though it appears on two security blocklists: PhishDestroy and ScamSniffer. The site employed a Let's Encrypt SSL certificate, which is commonly used by both legitimate and malicious actors to encrypt traffic. Additional technical indicators include the use of Nginx as a web server, along with tracking and analytics tools such as Yandex.Metrika, Google Tag Manager, Google Analytics, and Cloudflare Browser Insights, which are often leveraged to monitor victim interactions and optimize phishing efficacy. Current status indicates the domain has been taken offline, though the infrastructure may remain dormant for future use. Given the domain's creation date in the future (May 2026), this is likely a typographical error in the dataset; however, if accurate, it suggests highly irregular registration practices. Organizations and individuals are advised to treat any prior communications or transactions associated with heleket-invoice.com as fraudulent. Network administrators should block the IP address 188.114.96.3 and monitor for any resurgence of the domain or similar variants. End users should verify payment portals through official channels and report any suspicious activity to relevant security teams.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
VirusTotal
2 ← 0
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات
حُدّدت ٦ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of heleket-invoice.com · checked Jun 26, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب