الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 1. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

nightder[.]vip

“Nachtliebe”

حكم التهديد عالية 55/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
VirusTotal detections: 1 (vendor total unavailable)
16/11/2025

ملخص الأدلة

مرتفع
Evidence score
55/100

Analysis as of July 24, 2026 indicates that nightder.vip was actively used as a phishing portal before being taken offline. The domain was registered on September 8, 2025 through Gname.com Pte. Ltd. and is hosted on a Google Cloud infrastructure identified by ASN 396982 (Google LLC) with the public address 35.240.219.19 located in Singapore. Passive DNS shows the domain resolving to that IP and using the authoritative name servers a.share-dns.com, a10.share-dns.com, b.share-dns.net, and b10.share-dns.net. The site presented an SSL certificate issued by Let’s Encrypt (R13) and advertised the page title “Nachtliebe”.

Infrastructure fingerprinting detected Nginx serving the site, a Vue.js front‑end framework, and HTTP Strict Transport Security (HSTS) headers. A Gridinsoft trust score of 48 out of 100 reflects modest risk. VirusTotal scanning recorded a single positive detection among 95 AV engines, and the domain appears on one external blocklist that has been incorporated into the PhishDestroy takedown service, which confirmed the site’s phishing intent. The domain currently returns no HTTP response because it has been removed from service.

Defenders should immediately add nightder.vip and its resolved IP 35.240.219.19 to deny‑list rules, ensure that any outbound traffic to the associated name servers is monitored, and verify that existing URL filtering solutions incorporate the blocklist entry. Continued observation of the hosting ASN for new domains that resolve to the same IP range is advisable, as threat actors often recycle cloud resources. Because the content of the page has not been captured, investigators should request a forensic snapshot from any available web archives before the takedown for deeper attribution. In the absence of further indicators, the available evidence justifies a high‑confidence classification of nightder.vip as a phishing site and recommends persistent blocking across network perimeter and endpoint controls.

VirusTotal
VirusTotal
1 det.
شهادة TLS
R13 16d
العمر
11 mo
الحالة المرصودة
المحتوى غير متوفر HTTP 502
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 1 detections · vendor total unavailable URLQuery تم تخزين التقرير - الحكم التفصيلي معلق PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 14 تم الفحص — لا يوجد حظر TLS valid certificate, 16d WHOIS 11 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
مؤشرات الأمان
GS Gridinsoft Analysis
Hosting SSL Certificate No Access Young Domain

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
11/12

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. VirusTotal

    0 ← 1

لقطة محفوظة

عنوان الصفحة
Nachtliebe
شهادة TLS
Valid transport encryption · صادرة عن R13 · valid for 16 days

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN nginx · AS396982 GOOGLE-CLOUD-PLATFORM, US
سمعة عنوان IP IP abuse confidence 0/100 0 reports checked 17/06/2026
مسجّل النطاق Gname SG(SG)
جهة الإبلاغ عن إساءة الاستخدامmaster@share-dns.com, complaint@gname.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ nightder.vip →
عنوان IP 35.240.219.19 SG
الموقع الجغرافيSG Singapore, SG
الشبكةAS396982 · Google LLC
التسجيلتم إنشاؤه 08/09/2025 (336d) Expires 08/09/2026
حالة HTTP502 Error
الوقت حتى أول تعذّر للوصول 119 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف16/11/2025
DOM Analysisanalyzed 11/03/2026DOM analysis score 0/100
Submitted URLhttps://nightder.vip/
خوادم الأسماءa.share-dns.coma10.share-dns.comb.share-dns.netb10.share-dns.net
بصمة TLS
رصد TLSصالح منذ 16/12/2025فُحص في 11/03/2026
الأسماء البديلة لموضوع TLSnighiry.vipnighixw.vipnighoks.vipnightbvr.vipnightekx.vipnightlkj.vipnightsgj.vipnightshr.vipnighxio.vipwww.nighiry.vipwww.nighixw.vipwww.nighoks.vipwww.nightbvr.vipwww.nightder.vipwww.nightekx.vip+4
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

1 detections recorded · vendor total unavailable
View on VT
Last analyzed First positive detection Previous stored snapshot: 1 detection
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of nightder.vip · checked Mar 2, 2026

49
Poor
Performance
FCP
5.51s
First Contentful Paint
LCP
14.98s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
310ms
Total Blocking Time
SI
12.43s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

GridinsoftGridinsoft درجة الثقة 48/100الحالة: Suspiciousفتح المصدر
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/nightder.vip"
  title="PhishDestroy threat report for nightder.vip"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.