orldassets[.]entry-cryptolist[.]app
“CRYPTOLIST”
ملخص الأدلة
Analysis of the domain orldassets.entry-cryptolist.app, observed on 2026-07-29, classifies it as an active generic phishing infrastructure with an elevated risk rating. The domain resolves to the IPv4 address 188.114.97.3, which is currently listed on a single external blocklist and is explicitly blocked by the PhishDestroy mitigation service. DNS interrogation did not return any authoritative nameserver records, as indicated by the placeholder NS_NOT_FOUND, suggesting either deliberately concealed name server configuration or a failure in the query process. VirusTotal scanning shows that 15 out of 91 antivirus and URL-reputation engines have generated a malicious verdict for the domain, reinforcing the suspicion of phishing behavior.
The presence of multiple vendor detections, combined with the blocklist entry and active blocking by PhishDestroy, provides sufficient technical evidence for security teams to treat the domain as hostile. Uncertainties remain regarding the underlying web content, TLS certificate details, HTTP response codes, and the specific phishing lure employed, because these attributes have not been publicly disclosed or captured in the available intelligence. Consequently, the exact victim-targeting vector and any associated credential-harvesting pages cannot be described at this time.
Defenders should prioritize adding the domain to internal blocklists, enforce DNS sink-holing for the resolved IP address, and monitor network traffic for connections to 188.114.97.3. Additional sandbox or manual analysis of the live site, if safely isolated, would be required to obtain payload samples, page titles, and any embedded malicious scripts. Continuous re-evaluation is advised, as further detection updates from additional security vendors may alter the threat posture.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
-
VirusTotal
3 ← 15
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب