الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref 4BFE6AA4

MALICIOUS — HIGH

obtain-pol[.]com

The domain obtain-pol.com was registered on February 24, 2026 through NiceNIC International Group Co., Limited.

66/100 evidence score · High
VirusTotal
2/93
Blocklists
No stored match
التوفر
آخر نشاط معروف · HTTP 200
Report / Add Evidence Appeal this listing
2026-03-25 11:21 UTCآخر نشاط معروف · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
5 months
Reports sent
1
Latest case ID
PD-20260224-03521C
Current status
HTTP 200 at latest stored check
Jump to section
ملخص التقرير

obtain-pol.com — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Polygon; نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 2/93 (Fortinet, SOCRadar); PhishDestroy score 66/100. مسجّل النطاق: NiceNIC.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref 4BFE6AA4

The domain obtain-pol.com was registered on February 24, 2026 through NiceNIC International Group Co., Limited. It resolves to the Cloudflare‑hosted address 188.114.96.3, which is advertised as belonging to AS13335 Cloudflare, Inc. in the United States. The site presented an SSL certificate issued by Google Trust Services under the WE1 intermediate, indicating a valid TLS handshake and a HTTP 200 response at the time of capture. Public reputation checks show a Gridinsoft trust score of 0 out of 100, and the domain appears on a single security blocklist, currently listed by PhishDestroy. VirusTotal scanning recorded 2 positive detections out of 93 vendors, confirming that at least two security products flagged the site as malicious.

The nameservers nicolas.ns.cloudflare.com and ximena.ns.cloudflare.com are standard Cloudflare resolvers. Technical fingerprinting identified AngularJS, jQuery, a jQuery CDN, Cloudflare Browser Insights, and HTTP/3 support, all typical of a modern web application hosted behind Cloudflare. The page title returned “Global Settlement Network,” which does not directly reference the targeted brand but the intelligence attributes the campaign to a Wallet Connect Abuse kit and classifies the scam as wallet/seed phishing. The campaign impersonates Polygon, suggesting that any credential or seed phrase entered by a victim would be captured for unauthorized wallet access. The domain is currently taken offline, which limits immediate victim exposure but does not remove the underlying infrastructure.

Defenders should continue to monitor the IP address 188.114.96.3 and the associated Cloudflare account for re‑activation, add the domain to blocklists, and enforce strict filtering of any outbound connections to Cloudflare‑resolved hosts that are not part of approved services.

VirusTotal
VirusTotal
2 det.
شهادة TLS
منتهية الصلاحية أو غير متحقق منها -102d
العمر
6 mo
الحالة المرصودة
آخر نشاط معروف 200
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات12 recorded checks
VirusTotal 2 / 93 URLQuery checked — no detections recorded PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 6 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات Registrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
16/17
Sent Report Recorded
Stored sent-report record for registrar NiceNIC International Group Co., Limited, hosting provider, 1 abuse contact
abuse@nicenic.net
24/02/2026

حالة قوائم الحظر العامة

لقطة محفوظة

عنوان الصفحة
Global Settlement Network
شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن Google Trust Services / WE1

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN cloudflare · AS13335 CLOUDFLARENET - Cloudflare, Inc., US
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق NiceNIC RU(RU) PhishDestroy Investigation
جهة الإبلاغ عن إساءة الاستخدامabuse@nicenic.net
البحث في قاعدة بيانات WHOISICANN RDAP لـ obtain-pol.com →
عنوان IP 188.114.96.3 CDN
الموقع الجغرافيUS San Francisco, US
الشبكةAS13335 · Cloudflare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 24/02/2026 (165d)
Elapsed Since First Report 59 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: آخر نشاط معروف.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
حالة HTTP200
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف24/02/2026
DOM Analysisanalyzed 23/04/2026score 10/100
IoC Extractionscanned 02/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://obtain-pol.com/
خوادم الأسماءximena.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 30/01/2026scanned 15/03/2026
Case ID
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.

Latest Classified Outcome 2026-08-09 02:43:39 UTC

Primary outcome Live content reason: Ordinary HTTP content served 90% confidence
Attribution source: Current Http Probe
Evidence layers Availability: Content serving Content: Content served at root DNS: Resolved Registration: Active
Latest HTTP observation Live content Ordinary HTTP content served 90% 2026-08-09 02:43:39 UTC
RDAP registration نشط NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientTransferProhibited expires 2026-12-02 09:37:46 UTC checked 2026-08-05 18:50:10 UTC
Observed timeline last reachable: 2026-08-09 02:43:39 UTC last content: 2026-08-09 02:43:39 UTC
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
التقنيات · 6 identified
AngularJS
JavaScript frameworks

AngularJS is a JavaScript-based open-source web application framework led by the Angular Team at Google.

angularjs.org ثقة 100٪
jQuery CDN
CDN

jQuery CDN is a way to include jQuery in your website without actually downloading and keeping it your website's folder.

code.jquery.com ثقة 100٪
jQuery
JavaScript libraries

jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.

jquery.com ثقة 100٪
Cloudflare Browser Insights
Analytics RUM

Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.

www.cloudflare.com ثقة 100٪
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com ثقة 100٪
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org ثقة 100٪
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

2 / قام موردو الأمان 93 بوضع علامة على هذا المجال
View on VT
Last analyzed
Fortinet
SOCRadar

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260224-03521C Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org
Page title stored with report: Polygon | The Go-To Blockchain for Payments
نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/obtain-pol.com"
  title="PhishDestroy threat report for obtain-pol.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.