الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 5. قوائم الحظر العامة التي تبلغ عن تطابق: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

pay[.]ffoundation[.]io

“Online payment @ F Foundation”

حكم التهديد حرجة 80/100 درجة الأدلة
التوفر آخر نشاط معروف أحدث مراقبة إمكانية الوصول المخزنة
اكتشافات VirusTotal: 5/91 Spamhaus DBL: DBL_ABUSED_PHISH تطابقات القائمة السوداء المخزنة: 2 انتحال العلامة التجارية: Foundation آخر نشاط معروف
02/08/2026 Foundation

ملخص الأدلة

حرج
Evidence score
80/100

Analysis of the domain pay.ffoundation.io indicates that it is currently classified as a generic phishing infrastructure and remains active as of the report date, 02 August 2026. The domain was submitted to VirusTotal where it was examined by ninety‑one scanning engines; none of the engines have produced a detection at the time of analysis. While the absence of detections might suggest a lack of known malicious payloads, the result alone does not constitute evidence of safety, especially given the domain’s appearance on a security blocklist.

The blocklist entry is confirmed by PhishDestroy, which actively blocks traffic to the domain, reinforcing the suspicion that the domain is being used for phishing‑related campaigns. No additional public metadata such as Safe Browsing verdicts, Open Threat Exchange references, registrar details, IP address allocation, hosting provider, SSL certificate information, HTTP response codes, trust‑score metrics, or page‑title content has been released in the current intelligence set. Consequently, the specific operational tactics, targeted brands, or phishing kit employed by the infrastructure remain undetermined.

Defenders should continue to monitor pay.ffoundation.io for any changes in detection status across sandbox and telemetry platforms, enforce network‑level blocks consistent with existing blocklist entries, and consider incorporating the domain into internal URL filtering policies. Ongoing reconnaissance, including active probing of the site’s HTTP endpoints and retrieval of TLS certificate data, is recommended to gather further indicators that could clarify the threat’s scope and intent.

VirusTotal
VirusTotal
5 det.
شهادة TLS
GoDaddy.com, Inc. 29d
العمر
1.9 yr
الحالة المرصودة
آخر نشاط معروف HTTP 200
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 5 / 91 URLQuery لم يتم التحقق منها PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 29d WHOIS 23 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
12/14

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026

٨ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. أول تسجيل

    أول قيمة محفوظة: يمكن الوصول إليه

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN AmazonS3 · AS14618 AMAZON-AES - Amazon.com, Inc., US
سمعة عنوان IP IP abuse confidence 0/100 1 report checked 02/08/2026
Registrar (base domain) GoDaddy US(US)
عنوان IP 100.49.110.141 US
الموقع الجغرافيUS Ashburn, US
الشبكةAS14618 · Amazon.com, Inc.
Registration (base domain)ffoundation.io · تم إنشاؤه 30/09/2024 Expires 30/09/2026
حالة HTTP200
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف02/08/2026
DOM Analysisanalyzed 02/08/2026DOM analysis score 70/1001 brand signal
Submitted URLhttp://pay.ffoundation.io/
خوادم الأسماءns49.domaincontrol.comns50.domaincontrol.com
بصمة TLS
رصد TLSصالح منذ 01/09/2025فُحص في 02/08/2026
الأسماء البديلة لموضوع TLSwww.pay.ffoundation.io
Favicon Hash
عنوان الصفحة
Online payment @ F Foundation
Impersonates
Foundation
شهادة TLS
Valid transport encryption · صادرة عن GoDaddy.com, Inc. · valid for 29 days

التقنيات

حُدّدت تقنية واحدة عالية الثقة

Google Pay
Cloudflare Radar
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

5 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed First positive detection Previous stored snapshot: 5 detections
BitDefender
Forcepoint ThreatSeeker
G-Data
كاسبرسكي
SOCRadar

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/pay.ffoundation.io"
  title="PhishDestroy threat report for pay.ffoundation.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>