MALICIOUS — CRITICAL
فحص التصيد والأمان للنطاق jb3512.cc
jb3512[.]
This domain is flagged as an elevated-risk credential theft operation targeting Chinese-speaking users through the impersonation of 金贝娱乐, a recognized entertainment or gaming platform.
- VirusTotal
- 11/91
- Blocklists
- No stored match
- التوفر
- آخر نشاط معروف · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
jb3512.cc — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Generic; نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 93/100. مسجّل النطاق: NameCheap.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
This domain is flagged as an elevated-risk credential theft operation targeting Chinese-speaking users through the impersonation of 金贝娱乐, a recognized entertainment or gaming platform. Analysis indicates the site is designed to harvest login credentials, payment details, or personal information under false pretenses, with potential secondary payload delivery for account takeover or financial fraud. Infrastructure analysis reveals the domain jb3512.cc was registered on February 21, 2026, through NameCheap, Inc., and currently resolves to the IP address 182.16.17.115. The site uses a Let's Encrypt SSL certificate (R13) to present a false sense of legitimacy. Security telemetry shows 8 out of 95 vendors on VirusTotal flagged the domain as malicious, while AlienVault OTX recorded it in one threat intelligence pulse. The domain appears on a single security blocklist, and its page title, 金贝娱乐, directly mimics a legitimate brand to deceive visitors. Mitigation requires immediate blocking of the domain and associated IP (182.16.17.115) at the network perimeter. Users who may have interacted with the site should reset credentials for any accounts entered, particularly those linked to financial services or gaming platforms. Organizations should monitor for anomalous login attempts or unauthorized transactions originating from credentials potentially compromised via this phishing operation. Security teams are advised to review logs for connections to 182.16.17.115 and correlate with any reported credential theft incidents. Endpoint protection should be updated to detect and prevent access to this domain and related infrastructure.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Progressive JavaScript framework for building user interfaces.
Web platform based on Nginx with LuaJIT for scalable web apps.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of jb3512.cc · checked Mar 2, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.