hollythesquirrel[.]xyz
hollythesquirrel.xyz — المحتوى غير متوفر. ملخص الأدلة: VirusTotal 5/93 (alphaMountain.ai, Fortinet, Gridinsoft, Seclookup, SOCRadar); Spamhaus DBL_SPAM; PhishDestroy score 65/100. مسجّل النطاق: PDR.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of hollythesquirrel.xyz shows a domain created on December 29, 2025 and currently hosted behind Cloudflare infrastructure (ASN13335, United States). The domain resolves to IP address 172.67.223.162 and uses the Cloudflare nameservers amos.ns.cloudflare.com and dayana.ns.cloudflare.com. No TLS certificate is presented, indicating that the site is served without HTTPS encryption. A single HTTP response returned the page title "Just a moment...", which provides no additional context about the content or intended victim brand.
The domain is registered through PDR Ltd. d/b/a PublicDomainRegistry.com. Security telemetry indicates that five of ninety-three VirusTotal scanners flagged the domain, and it is listed on one security blocklist, specifically PhishDestroy, confirming that at least one reputable anti‑phishing feed has recognized it as malicious. Gridinsoft assigned a trust score of 0 out of 100, reinforcing the low confidence in its legitimacy. The site has been taken offline, but historical evidence suggests a generic phishing campaign.
Uncertainty remains regarding the specific brand or credential target, as no brand name appears in the page title or other collected attributes. Defenders should immediately block hollythesquirrel.xyz at DNS and proxy layers, monitor for any future resolution to the same Cloudflare IP range, and update intrusion detection signatures to flag HTTP responses containing the "Just a moment..." title from this domain. Continuous observation of the underlying Cloudflare IP block for any resurgence of phishing activity is advised, as infrastructure reuse is common in such campaigns.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب