الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 5. قوائم الحظر العامة التي تبلغ عن تطابق: 1. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

nongwan[.]memepasses[.]io

“MEMEPASS — Season I”

حكم التهديد حرجة 80/100 درجة الأدلة
التوفر آخر نشاط معروف أحدث مراقبة إمكانية الوصول المخزنة
اكتشافات VirusTotal: 5/91 Spamhaus DBL: DBL_SPAM تطابقات القائمة السوداء المخزنة: 1 آخر نشاط معروف
27/07/2026 CDN
ملخص التقرير

nongwan.memepasses.io — آخر نشاط معروف (HTTP 200). ملخص الأدلة: VirusTotal 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_SPAM; 1 external blocklist match (ScamSniffer); PhishDestroy score 80/100. مسجّل النطاق: NiceNIC.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
0F2BBC8D
الدرجة
80/100

The domain nongwan.memepasses.io was registered on July 17 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently hosted on the Cloudflare network, using nameservers ashley.ns.cloudflare.com and jasper.ns.cloudflare.com. DNS resolution points to IP address 188.114.97.3, an address regularly associated with Cloudflare edge nodes. The domain is listed as active and has been observed on a single security blocklist; it is also flagged by the PhishDestroy blocklist.

A VirusTotal scan performed on the domain involved 91 anti‑malware vendors, none of which raised a detection at the time of analysis. The absence of detections does not constitute a safety guarantee, as the scan may not reflect the latest payload or content changes. No public Safe Browsing, OTX, SSL certificate, HTTP status, or page‑title information is presently available for this domain, limiting the depth of technical fingerprinting.

Given the recent creation date, the use of Cloudflare infrastructure, and the blocklist entries, the domain exhibits characteristics commonly associated with newly deployed phishing infrastructure. Defenders should consider adding the domain to local deny lists, monitoring DNS queries for the associated IP, and reviewing any outbound traffic that may attempt to resolve or contact the domain. Continuous re‑evaluation is advised, as the threat posture may evolve.

VirusTotal
VirusTotal
5 det.
شهادة TLS
Google Trust Services
العمر
1 mo New
الحالة المرصودة
آخر نشاط معروف 200
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 5 / 91 URLQuery لم يتم التحقق منها PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 87d WHOIS 1 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات Registrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
12/14

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
Registrar (base domain) NiceNIC RU(RU) PhishDestroy Investigation
عنوان IP 188.114.97.3 CDN
الموقع الجغرافيCA Toronto, CA
الشبكةAS13335 · CloudFlare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
Registration (base domain)memepasses.io · تم إنشاؤه 17/07/2026 (31d · New) Expires 17/07/2027
حالة HTTP200
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف27/07/2026
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://nongwan.memepasses.io/
خوادم الأسماءashley.ns.cloudflare.comjasper.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 24/07/2026scanned 27/07/2026
TLS SAN Domainsmemepasses.io
Favicon Hash
عنوان الصفحة
MEMEPASS — Season I
شهادة TLS
Valid transport encryption · صادرة عن Google Trust Services · valid for 87 days

Latest Classified Outcome 2026-08-17 02:46:20 UTC

Primary outcome Live content reason: Ordinary HTTP content served 90% confidence
Attribution source: Current Http Probe
Evidence layers Availability: Content serving Content: Content served at root DNS: Resolved Registration: Unknown
Latest HTTP observation Live content Ordinary HTTP content served 90% 2026-08-17 02:46:20 UTC
RDAP registration غير معروف
Observed timeline last reachable: 2026-08-17 02:46:20 UTC last content: 2026-08-17 02:46:20 UTC
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
التقنيات · 3 identified
Cloudflare Browser Insights
Analytics RUM

Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.

www.cloudflare.com ثقة 100٪
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com ثقة 100٪
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org ثقة 100٪
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

5 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed First positive detection Previous stored snapshot: 5 detections
alphaMountain.ai
CRDF
Fortinet
Gridinsoft
SOCRadar

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of nongwan.memepasses.io · checked Jul 27, 2026

85
Needs Work
Performance
FCP
2.77s
First Contentful Paint
LCP
3.7s
Largest Contentful Paint
CLS
0.048
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
2.77s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/nongwan.memepasses.io"
  title="PhishDestroy threat report for nongwan.memepasses.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>