الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 17. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

jon[.]whm[.]116-193-191-4[.]cpanel[.]site

“Meta Support”

حكم التهديد حرجة 95/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 17/94 Spamhaus DBL: DBL_MALWARE انتحال العلامة التجارية: Facebook
07/03/2026 Facebook
ملخص التقرير

jon.whm.116-193-191-4.cpanel.site — المحتوى غير متوفر. انتحال العلامة التجارية: Facebook; نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 17/94 (ADMINUSLabs, Cluster25, CyRadar, DNS8, Ermes); URLScan malicious verdict; Spamhaus DBL_MALWARE; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: Tucows.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
89E0B82D
الدرجة
95/100

This domain, jon.whm.116-193-191-4.cpanel.site, operates as a fraudulent credential-harvesting portal designed to mimic legitimate Meta Support pages. Visitors are presented with a deceptive login interface that closely resembles official Meta properties, including Facebook and Instagram support channels. The site is engineered to capture sensitive user credentials, such as usernames, passwords, and potentially two-factor authentication codes, which are then transmitted to unauthorized third parties. Such stolen credentials are frequently exploited for account takeovers, financial fraud, or further phishing campaigns targeting connected contacts. The presence of this site poses a direct risk to individual privacy and organizational security, particularly for users who may be tricked into believing they are interacting with authentic Meta support services. Analysis indicates this domain exhibits multiple high-risk characteristics consistent with phishing infrastructure. The domain was registered on March 07, 2026, through Tucows Domains Inc., an unusually recent creation date that deviates from established legitimate support portals. It resolves to the IP address 116.193.191.4, hosted within AS136052 (PT Cloud Hosting Indonesia), a network segment frequently associated with transient or malicious hosting. Notably, the domain lacks a valid SSL certificate, increasing the likelihood of unencrypted credential transmission. Security validation engines have flagged this domain as malicious, with 17 out of 95 vendors on VirusTotal detecting it as a phishing threat. Additionally, the domain appears on at least one security blocklist and is currently offline, suggesting prior detection and remediation efforts by hosting providers or security entities. Users who have interacted with jon.whm.116-193-191-4.cpanel.site should take immediate corrective actions to mitigate potential compromise. First, reset passwords for any accounts accessed or entered on the site, prioritizing Meta-related services such as Facebook, Instagram, and associated email accounts. Enable multi-factor authentication (MFA) using app-based or hardware tokens rather than SMS-based methods, which may be vulnerable to interception. Review account activity logs for unauthorized access or suspicious actions, such as unrecognized logins, message sends, or profile changes. If financial or payment information was submitted, monitor bank statements and credit reports for fraudulent transactions, and consider placing a fraud alert with relevant credit bureaus. Finally, report the domain to local cybersecurity authorities or consumer protection agencies to assist in broader threat mitigation efforts.

VirusTotal
VirusTotal
17 det.
رادار CF
ضار
العمر
6 mo
الحالة المرصودة
المحتوى غير متوفر
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 17 / 94 URLQuery لم يتم التحقق منها PhishStats checked — no match recorded OTX no community references رادار CF provider verdict: malicious URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS لم يتم التحقق منها TLS لا توجد بيانات للشهادة WHOIS 6 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
CF Cloudflare Radar Verdict ضار
Phishing Phishing Security threats
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer:

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
15/16

حالة قوائم الحظر العامة

لقطة محفوظة

عنوان الصفحة
Meta Support
Impersonates
Facebook Instagram

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: Facebook report ↗
الخادم / ASN LiteSpeed · AS136052 PT Cloud Hosting Indonesia
سمعة عنوان IP abuse score 0/100 0 reports checked 14/07/2026
Registrar (base domain) Tucows CA(CA)
جهة الإبلاغ عن إساءة الاستخدامdomainabuse@tucows.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ cpanel.site →
عنوان IP 116.193.191.4 ID
الموقع الجغرافيID Jakarta, ID
الشبكةAS136052 · PT Cloud Hosting Indonesia
Registration (base domain)cpanel.site · تم إنشاؤه 07/03/2026 (167d)
الوقت حتى أول تعذّر للوصول 33h
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف07/03/2026
DOM Analysisanalyzed 29/07/2026score 73/1002 brand signals
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://jon.whm.116-193-191-4.cpanel.site/
TLS Observationvalid from 18/02/2026scanned 15/03/2026
ICANN OVERSIGHT Registration: cpanel.site

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain cpanel.site behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
التقنيات · 8 identified
Tailwind CSS
UI frameworks

Utility-first CSS framework for rapid custom UI development.

LiteSpeed
Web servers

High-performance web server compatible with Apache configurations.

Cloudflare
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
J
jQuery CDN

Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.

jQuery
JavaScript libraries

Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.

Google Hosted Libraries
cdnjs
HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

17 / قام موردو الأمان 94 بوضع علامة على هذا المجال
View on VT
Last analyzed
ADMINUSLabs
Cluster25
CyRadar
DNS8
Ermes
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
كاسبرسكي
Lionic
نتكرافت
OpenPhish
Seclookup
سوفوس
Webroot

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/jon.whm.116-193-191-4.cpanel.site"
  title="PhishDestroy threat report for jon.whm.116-193-191-4.cpanel.site"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.