open-sea-io-cdn[.]pages[.]dev
“OpenSea Wallet Log In - Secure NFT Access”
open-sea-io-cdn.pages.dev — المحتوى غير متوفر. انتحال العلامة التجارية: OpenSea; نوع الاحتيال: Seed Phrase Theft. ملخص الأدلة: VirusTotal 5/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CyRadar, Fortinet); PhishDestroy score 65/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain open-sea-io-cdn.pages.dev was observed on July 23, 2026 and is currently listed as offline. Registration information indicates the domain was created on February 21, 2026 and is hosted through Cloudflare, Inc., with authoritative nameservers eve.ns.cloudflare.com and jaxson.ns.cloudflare.com. DNS resolution points to the IP address 172.66.44.91, which belongs to AS13335 Cloudflare and is geolocated in the United States. The TLS certificate presented is issued by Google Trust Services under the WE1 root, confirming that the site leveraged a valid HTTPS connection.
HTTP response headers include HSTS and the site supports HTTP/3, both typical of Cloudflare‑served content. The page title returned by the server is “OpenSea Wallet Log In - Secure NFT Access”, and the domain is explicitly marked as impersonating the OpenSea brand, consistent with a wallet/seed phishing campaign. VirusTotal has recorded five positive detections out of ninety‑three scanners, and the domain appears on a single external blocklist maintained by PhishDestroy. Independent reputation scoring from Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the malicious classification.
The HTTP status code observed was 403, indicating that direct content retrieval was blocked at the time of testing. While the available data confirms the infrastructure, the exact phishing payload and any associated command‑and‑control endpoints remain unknown because the site was not reachable for content analysis. Defenders should continue to block the domain at network perimeter, add the IP address 172.66.44.91 to deny lists, and monitor for any future re‑registration of similar subdomains under the pages.dev namespace. Ongoing vigilance is advised for credential‑harvesting attempts targeting OpenSea users, especially those that reference wallet access or seed phrases.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
التقنيات · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of open-sea-io-cdn.pages.dev · checked Mar 25, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب