الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 15. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
4 months
Reports sent
1
Current status
HTTP 302 at latest stored check
أمن المجال وذكاء التهديدات

mail[.]fantintonline[.]com

“Fantagio Investment”

حكم التهديد حرجة 100/100 درجة الأدلة
التوفر آخر نشاط معروف أحدث مراقبة إمكانية الوصول المخزنة
اكتشافات VirusTotal: 15/91 URLQuery threat systems: 1 alert انتحال العلامة التجارية: Genericscam آخر نشاط معروف
07/04/2026 Genericscam 1 Report Sent

ملخص الأدلة

حرج
Evidence score
100/100

The domain mail.fantintonline.com is currently active and classified as a high‑risk generic phishing site targeting investment victims. DNS resolution points to the IPv4 address 79.133.41.250, which is hosted in Germany and associated with UltaHost Inc. The authoritative name servers are ns1.ultahost.com and ns2.ultahost.com. The domain was registered on April 07, 2026 through TuringSign Inc. d/b/a Cosmotown and uses a Let’s Encrypt R13 certificate. An HTTP 302 response is observed, and the page title presented to visitors reads "Fantagio Investment". Gridinsoft assigns a trust score of 0 out of 100, indicating severe suspicion. The site is listed on a single security blocklist and has been blocked by the PhishDestroy feed. VirusTotal reports 17 of 94 security vendors flagging the domain, reinforcing its malicious reputation. While the precise phishing payload has not been disclosed, the combination of an investment‑oriented title, low trust score, and multiple vendor detections suggests credential‑stealing or financial fraud aimed at unwary investors. Defenders should block DNS resolution to 79.133.41.250, add mail.fantintonline.com to URL filtering policies, and monitor for related email campaigns referencing "Fantagio Investment". Continued observation is advised to capture any evolving infrastructure or payload changes.

لقطة الأدلة المرسلة

أُرسل
سجلات الدفتر
1
معرّف القضية
PD-20260407-45C148
عنوان الصفحة الملتقطة
Fantagio Investment
ملف PDF
دليل PDF
النص الكامل للدليل
Policy Violations:
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
VirusTotal
VirusTotal
15 det.
URLQuery
URLQuery
1 threat alert
DNS Security
1/12
شهادة TLS
منتهية الصلاحية أو غير متحقق منها
العمر
4 mo
الحالة المرصودة
آخر نشاط معروف HTTP 302
PhishDestroy
قائمة الإتلاف
مدرج
Reports Sent
1

Data Coverage

VirusTotal 15 / 91 URLQuery 1 threat-system alert PhishStats checked — no match recorded OTX no community references رادار CF no data URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS 1/12 TLS منتهية الصلاحية أو غير متحقق منها WHOIS 4 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
DNS Provider Blocks 1 / 12
Brand Ton
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
Private YARA rules www.youtube.com/s/player/8c83ec2e/player_embed_es6.vflset/en_us/base.js audit Hunting_JS_WebAssembly
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer:

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
12/13

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. VirusTotal

    None ← 2

  2. VirusTotal

    3 ← 12

  3. VirusTotal

    12 ← 17

لقطة محفوظة

عنوان الصفحة
Fantagio Investment
شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن Let's Encrypt / R13

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing report ↗
الخادم / ASN LiteSpeed · AS214036 Ultahost, Inc.
سمعة عنوان IP IP abuse confidence 0/100 1 report checked 14/07/2026
Registrar (base domain) TuringSign
جهة الإبلاغ عن إساءة الاستخدامabuse@cosmotown.com, abuse@first-colo.net, u-abuse@ultahost.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ fantintonline.com →
عنوان IP 79.133.41.250 DE
الموقع الجغرافيDE Frankfurt am Main, DE
الشبكةAS214036 · UltaHost Inc
Registration (base domain)fantintonline.com · تم إنشاؤه 07/04/2026 (126d)
حالة HTTP302 Found (Temporary)
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف07/04/2026
Submitted URLhttp://mail.fantintonline.com/
خوادم الأسماءns2.ultahost.com
بصمة TLS
رصد TLSصالح منذ 31/03/2026فُحص في 08/04/2026
الأسماء البديلة لموضوع TLSautodiscover.fantintonline.comcpanel.fantintonline.comcpcalendars.fantintonline.comcpcontacts.fantintonline.comfantintonline.comwebdisk.fantintonline.comwebmail.fantintonline.comwww.fantintonline.com
ICANN OVERSIGHT Registration: fantintonline.com

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain fantintonline.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.

الاستخبارات الجنائية الرقمية

External Scripts 4
http://html5shiv.googlecode.com/svn/trunk/html5.js https://cdn.gtranslate.net/widgets/latest/popup.js https://widgets.coingecko.com/coingecko-coin-price-marquee-widget.js https://translate.google.com/translate_a/elementa0d8.js?cb=googleTranslateElementInit
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

15 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 17 detections
ChainPatrol
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
كاسبرسكي
Lionic
SOCRadar
سوفوس
VIPRE
Webroot
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of mail.fantintonline.com · checked Jun 26, 2026

49
Poor
Performance
FCP
10.27s
First Contentful Paint
LCP
16.9s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
319ms
Total Blocking Time
SI
10.27s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/mail.fantintonline.com"
  title="PhishDestroy threat report for mail.fantintonline.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.