login-group-id[.]online
“WhatsApp”
login-group-id.online — المحتوى غير متوفر. انتحال العلامة التجارية: WhatsApp; نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 17/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); PhishDestroy score 95/100. مسجّل النطاق: PDR.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
On July 23, 2026, analysis confirms that the domain login-group-id.online is being used for brand impersonation targeting WhatsApp users. The site’s page title is reported as "WhatsApp," indicating a direct attempt to lure victims into submitting credentials. The domain was registered on October 20, 2025 through PDR Ltd. d/b/a PublicDomainRegistry.com and is hosted on the IP address 138.124.108.128, which resolves to a server in Germany owned to AS210644 AEZA GROUP LLC. The hosting environment is identified by four timeweb nameservers (ns1.timeweb.ru, ns2.timeweb.ru, ns3.timeweb.org, ns4.timeweb.org). No SSL certificate is present, and the site is currently taken offline, suggesting the operators may be monitoring takedown actions.
Reputation data shows a Gridinsoft trust score of 0 out of 100 and the domain appears on one security blocklist. It has been cited in 17 AlienVault OTX threat pulses, reinforcing its association with malicious campaigns. VirusTotal scans have recorded 17 detections out of 95 security vendors, confirming that multiple antivirus and URL‑filtering products flag the domain as malicious. The domain is also blocked by the PhishDestroy service.
The observed activity aligns with credential‑phishing tactics, where attackers typically harvest login details for the WhatsApp service. Uncertainty remains regarding the exact phishing kit or any additional infrastructure components, as no further page content or external links have been disclosed. Defenders should add the IP address 138.124.108.128 and the domain login-group-id.online to block lists, enforce TLS inspection to identify any future unencrypted redirects, and monitor for similar timeweb name‑server patterns. Continuous threat‑intel feeds should be consulted for any resurgence of the domain, and any inbound traffic to the IP should be logged and investigated for potential credential harvesting attempts.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب