leprabit[.]com
فحص التصيد والأمان للنطاق leprabit.com
“Buy & Sell Bitcoin, Ethereum | Cryptocurrency Exchange | LEPRABIT”
leprabit.com — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Ethereum; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VT 3/93 (Gridinsoft, SOCRadar, URLQuery); URLQuery 2 det.; URLScan no malicious verdict; GSB no flag; BL 2 (MetaMask, SEAL); PD 71/100. مسجّل النطاق: CNOBIN INFORMATION TEC….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy first observed leprabit.com on Feb 3, 2026. Positive findings were recorded by VirusTotal, MetaMask, SEAL, and URLQuery. Evidence score: 71/100.
VirusTotal recorded 3 detections among 93 engines: Gridinsoft, SOCRadar, URLQuery on Feb 23, 2026 at 11:46 UTC. The external blocklist snapshot contained 2 matches (MetaMask, SEAL) on Aug 7, 2026 at 14:20 UTC. URLQuery recorded 2 detections on Feb 3, 2026 at 22:30 UTC. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0) on Feb 3, 2026 at 20:34 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:19 UTC; content was unavailable. Registration records list CNOBIN INFORMATION TECHNOLOGY LIMITED as the registrar. At collection time, the domain resolved to 172.67.158.112. Collected metadata identifies Ethereum as the apparent target. Captured page title: “Buy & Sell Bitcoin, Ethereum | Cryptocurrency Exchange | LEPRABIT”. PhishDestroy classified the observed content as Crypto Scam. DOM analysis completed on Apr 23, 2026 at 07:21 UTC; stored DOM score 0/100. IoC extraction completed on Aug 2, 2026 at 04:14 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis24/07/2026
Analysis of the domain leprabit.com indicates it was a cryptocurrency scam site impersonating Ethereum, operational until recently taken offline. The domain was registered on February 21, 2026, through CNOBIN INFORMATION TECHNOLOGY LIMITED and resolved to the IP address 172.67.158.112, hosted on Cloudflare's infrastructure (AS13335) in the United States. The site's page title, 'Buy & Sell Bitcoin, Ethereum | Cryptocurrency Exchange | LEPRABIT,' explicitly targeted cryptocurrency users, aligning with the 'Crypto Scam' classification in available threat intelligence. No SSL certificate was present, which is atypical for legitimate financial platforms and increases the risk of data interception.
The domain was flagged by three security blocklists, including PhishDestroy, MetaMask, and SEAL, and received a trust score of 0/100 from Gridinsoft. VirusTotal detections were limited, with only 3 of 93 security vendors marking the domain as malicious, suggesting either early-stage detection or evasion techniques. Nameservers were hosted under Cloudflare (bradley.ns.cloudflare.com and isla.ns.cloudflare.com), a common tactic to obscure hosting origins and leverage Cloudflare's proxy services for anonymity. The domain's current status is offline, but its infrastructure and registration details remain relevant for historical analysis and potential re-emergence under similar naming conventions.
Defenders should treat this domain as part of a broader cryptocurrency phishing campaign, particularly given its explicit impersonation of Ethereum. Monitoring for related domains registered through the same registrar or resolving to the same IP range may help identify future threats. Organizations should ensure blocklist updates include this domain and consider proactive filtering of newly registered domains with similar naming patterns or registrars.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
حصلت ICANN على أموالها. أما المساءلة فلم تصل.
بالنسبة إلى نطاق gTLD هذا، يعمل المسجّل المذكور أعلاه بموجب عقد مع ICANN. وتحصّل ICANN رسوماً سنوية ومتغيرة ورسومًا قائمة على المعاملات مرتبطة بعمليات التسجيل والتجديد والنقل.
الاعتماد: جرت الاستفادة منه مالياً. المساءلة: يُرجى التحقق مرة أخرى لاحقاً.
ثم يبدأ السحر: تكتب ICANN البند RAA §3.18، ويتولى المسجّل التحقيق في إساءة الاستخدام داخل قاعدة عملائه، ويقدّم الضحايا الأدلة مجاناً، بينما تنتظر كل طبقة أن يتحرك طرف آخر. إذا كان ذلك يجعل الضحايا يشعرون بمزيد من الأمان، فممتاز—لقد أدّت الفاتورة مهمتها.
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
حول هذا التقرير: leprabit.com
يقدم هذا التقرير أحدث الأدلة المخزنة المتاحة لـ PhishDestroy. يتم عرض الطوابع الزمنية للمصدر حيثما كان ذلك متاحًا؛ يمكن أن تتغير أحكام التوفر والبائعين بعد التجميع.
عرض الموقع الذي تم التقاطه عنوان الصفحة “Buy & Sell Bitcoin, Ethereum | Cryptocurrency Exchange | LEPRABIT” وربما ينتحل شخصية Ethereum.
اعتبارًا من 07/08/2026، كان لدى leprabit.com اكتشافات من محركات الأمان 3.
إذا كنت تعتقد أن هذه القائمة غير دقيقة، تقديم استئناف. للتعرف على منهجيتنا، قم بزيارة صفحة الأسئلة الشائعة.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب