الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 15. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

mail[.]newemalacessrobln[.]duckdns[.]org

“Default Web Site Page”

حكم التهديد حرجة 95/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 15/93
26/02/2026
ملخص التقرير

mail.newemalacessrobln.duckdns.org — المحتوى غير متوفر. ملخص الأدلة: VirusTotal 15/93 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: Gandi SAS.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
57BCB193
الدرجة
95/100

The domain mail.newemalacessrobln.duckdns.org was registered through Gandi SAS and has a creation date of 12 April 2013. DNS resolution points to the IPv4 address 162.241.124.87, which is announced by AS19871 Network Solutions, LLC and geolocated to the United States. The authoritative name servers are ns1.duckdns.org, ns2.duckdns.org and ns3.duckdns.org. No TLS certificate is presented; HTTP connections are served without encryption. The only visible HTML element is a page title of “Default Web Site Page”, indicating that the site is hosted on a generic web server and no further content has been captured.

Security telemetry shows the domain is currently offline, yet it was previously listed on a single public blocklist and is actively blocked by the PhishDestroy sinkhole. Google Safe Browsing classifies the URL as a social‑engineering threat, and VirusTotal reports that 15 of 93 scanned scanners flagged the host as malicious. The detection ratio suggests a moderate level of confidence among antivirus engines, but the limited number of scanners that observed the site reduces the overall certainty. Analysis confirms that the infrastructure is typical of low‑effort phishing campaigns that rely on dynamic DNS services such as DuckDNS.

The lack of an SSL certificate and the generic page title further point to a placeholder site rather than a fully developed phishing landing page. Because the domain is already taken offline, immediate containment is not required, but defenders should continue to monitor the associated IP address and the three DuckDNS name servers for any re‑activation. Adding the IP 162.241.124.87 and the domain to local block lists, as well as updating URL filtering rules to include the DuckDNS sub‑domain pattern, will help prevent future connections. Continuous observation of VirusTotal and Google Safe Browsing updates is recommended to capture any resurgence of malicious activity.

VirusTotal
VirusTotal
15 det.
رادار CF
ضار
العمر
13.4 yr
الحالة المرصودة
المحتوى غير متوفر
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 15 / 93 URLQuery لم يتم التحقق منها PhishStats checked — no match recorded OTX no community references رادار CF provider verdict: malicious URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS لا توجد بيانات للشهادة WHOIS 163 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
CF Cloudflare Radar Verdict ضار
Security threats Phishing Phishing

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
11/12

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
Google Safe Browsing تم وضع علامة عليها Social engineering checked 02/03/2026
الخادم / ASN Apache · AS19871 NETWORK-SOLUTIONS-HOSTING, US
سمعة عنوان IP abuse score 0/100 1 report checked 15/06/2026
مزود المنصة Gandi SAS FR(FR)
جهة الإبلاغ عن إساءة الاستخدامabuse@support.gandi.net
عنوان IP 162.241.124.87 US
الموقع الجغرافيUS Atlanta, US
الشبكةAS19871 · Network Solutions, LLC
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف26/02/2026
DOM Analysisanalyzed 29/07/2026score 0/100
IoC Extractionscanned 02/08/20260 wallet · 0 Telegram IoCs
خوادم الأسماءns3.duckdns.org
TLS Observationscanned 15/03/2026
عنوان الصفحة
Default Web Site Page
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

15 / قام موردو الأمان 93 بوضع علامة على هذا المجال
View on VT
Last analyzed
ADMINUSLabs
Criminal IP
BitDefender
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Google Safebrowsing
كاسبرسكي
Lionic
Phishing Database
سوفوس
VIPRE
Webroot

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/mail.newemalacessrobln.duckdns.org"
  title="PhishDestroy threat report for mail.newemalacessrobln.duckdns.org"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>