ksm-china[.]com
“Kusama官网”
ملخص الأدلة
The domain ksm-china.com was observed hosting a cryptocurrency‑related impersonation campaign targeting the Kraken exchange. The site was secured with a Let’s Encrypt R12 certificate, indicating a recent TLS deployment but offering no authentication of ownership. DNS resolution points to 172.67.172.57, an IP owned by Cloudflare (AS13335) located in the United States, and the authoritative name servers are decker.ns.cloudflare.com and tricia.ns.cloudflare.com, both Cloudflare‑managed. HTTP requests return a 403 status, suggesting the content is currently inaccessible; the host has been taken offline and is listed as such by multiple sink‑hole services. The page title returned during the brief probe was “Kusama官网”, a Chinese phrase meaning “Kusama official website”, which does not match the advertised Kraken brand and may be an attempt to lure Chinese‑speaking users.
Technical fingerprinting shows the server runs Apache HTTP Server with PHP support, a common stack for cheaply hosted scam pages. Registration data indicates the domain was created on 29 March 2021 through Dynadot LLC, a registrar frequently used for disposable domains. Reputation checks show the domain appears on two independent blocklists, and both PhishDestroy and Enkrypt have flagged it as malicious. VirusTotal recorded a single positive detection out of 95 scanners, reinforcing the suspicion of malicious intent. Independent scoring services assign a Gridinsoft trust score of 0 / 100, effectively marking the site as untrusted.
The campaign is classified as a crypto scam, with the explicit claim of impersonating Kraken. No additional evidence such as phishing form URLs, credential harvest endpoints, or malware payloads has been captured, leaving the exact attack vector unknown. Defenders should block DNS resolution for ksm-china.com, add the IP address 172.67.172.57 to network‑level deny lists, and ensure that any alerts referencing Kraken‑related credential theft are correlated with this indicator.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
بلاغات المجتمع
أبلغ عنه عضو واحد في المجتمع؛ شوهد أول مرة في 09/08/2025
- البلاغات المحفوظة
- 1
- عناوين URL الفريدة المبلغ عنها
- 1
معلومات المجتمع
بلاغان مجتمعيان
الفئةPHISHING
@angelsupport
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات
حُدّدَت تقنيتان عاليتا الثقة
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of ksm-china.com · checked Mar 2, 2026
نطاقات متشابهة
١١٤ نطاقًا متشابهًا محفوظًا
عرض الكل (88)
عرض 100 من 114
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب