الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 6. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

ppd[.]cpi[.]mybluehost[.]me

“Welcome -”

حكم التهديد حرجة 93/100 درجة الأدلة
التوفر مغطى بعباءة · يمكن الوصول إليه تمت ملاحظة إمكانية الوصول من خلال عمليات فحص إخفاء الهوية
اكتشافات VirusTotal: 6/91 نوع الاحتيال: Generic Phishing آخر نشاط معروف
21/03/2026
ملخص التقرير

ppd.cpi.mybluehost.me — مغطى بعباءة · يمكن الوصول إليه. نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, ESET, Gridinsoft, LevelBlue); cloaking observed; PhishDestroy score 93/100. مسجّل النطاق: Domain.com.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
08DF62D7
الدرجة
93/100

This domain, ppd.cpi.mybluehost.me, is flagged as an active phishing threat with high-risk indicators. Registered on March 22, 2026, through a commercial registrar, it resolves to IP address 50.6.34.104, hosted on infrastructure associated with Oracle Corporation in Germany. The domain is currently active, returning an HTTP 302 redirect status, which is commonly used in phishing campaigns to obscure final landing pages or evade detection. Infrastructure analysis reveals the use of WordPress, PHP, MySQL, and Nginx, alongside common web technologies such as jQuery and Yoast SEO, suggesting a standard but potentially compromised web stack. Security vendors have flagged the domain, with 8 out of 94 engines detecting malicious activity, though the specific nature of the phishing content remains unconfirmed. The domain appears on at least one security blocklist and is actively blocked by enterprise phishing protection systems. SSL certification is provided by Let’s Encrypt, a common choice for both legitimate and malicious sites due to its free and automated issuance process. Nameservers are hosted under mybluehost.me, a subdomain of a known hosting provider, which may indicate the use of shared or reseller hosting infrastructure. MX records point to mail.ppd.cpi.mybluehost.me, suggesting the domain may be used for email-based phishing or credential harvesting. The page title, 'Welcome -', provides no specific brand or target information, and no confirmed phishing kit or impersonated entity has been identified in available data. Defenders should treat this domain as a confirmed phishing threat, block resolution at the DNS level, and monitor associated IP and hosting infrastructure for related activity. Further analysis of the redirect chain and final landing page is recommended to determine the exact phishing methodology and potential brand impersonation.

VirusTotal
VirusTotal
6 det.
DNS Security
3/14
شهادة TLS
Let's Encrypt
الحالة المرصودة
مغطى بعباءة · يمكن الوصول إليه
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 6 / 91 URLQuery لم يتم التحقق منها PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 3/14 TLS valid certificate, 64d WHOIS not parsed لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
DNS Provider Blocks 3 / 14
Controld Adblock Controld Family Controld Malware

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
11/13

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN Apache · AS31898 Oracle Corporation
سمعة عنوان IP abuse score 0/100 0 reports checked 13/08/2026
Registrar (base domain) Domain.com
عنوان IP 50.6.34.104 DE
الموقع الجغرافيDE Frankfurt am Main, DE
الشبكةAS31898 · Oracle Corporation
Cloaking Cloaking Detected Redirect split · score 4/6
unavailable: raw=proxy_error; http=0; via=http_proxy; error=HTTPConnectionPool(host='45.249.59.12', port=5988): Max retries exceeded with url: http://ppd.cpi.mybluehost.me/ (Caused
checked 16/08/2026
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف21/03/2026
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://ppd.cpi.mybluehost.me/
خوادم الأسماءns1.mybluehost.mens2.mybluehost.me
MX Records0 mail.ppd.cpi.mybluehost.me
TLS Fingerprint
TLS Observationvalid from 24/02/2026scanned 25/03/2026
TLS SAN Domainsautodiscover.ppd.cpi.mybluehost.mecpanel.ppd.cpi.mybluehost.mecpcalendars.ppd.cpi.mybluehost.mecpcontacts.ppd.cpi.mybluehost.memail.ppd.cpi.mybluehost.mewebdisk.ppd.cpi.mybluehost.mewebmail.ppd.cpi.mybluehost.mewww.ppd.cpi.mybluehost.me
عنوان الصفحة
Welcome -
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 64 days
التقنيات · 9 identified
WordPress
CMS

Open-source CMS powering over 40% of websites worldwide.

MySQL
Databases

Open-source relational database management system.

PHP
Programming languages

Server-side scripting language designed for web development.

Yoast SEO
Nginx
Web servers Reverse proxies

High-performance HTTP server and reverse proxy, known for stability and low resource usage.

Apache HTTP Server
Web servers

Most widely used open-source HTTP server software.

jQuery Migrate
JavaScript libraries

Plugin to detect and restore deprecated jQuery features.

jQuery
JavaScript libraries

Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.

Bluehost
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

6 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 8 detections
alphaMountain.ai
Chong Lua Dao
ESET
Gridinsoft
LevelBlue
Webroot
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of ppd.cpi.mybluehost.me · checked Mar 21, 2026

89
Needs Work
Performance
FCP
2.27s
First Contentful Paint
LCP
3.25s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
3.38s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/ppd.cpi.mybluehost.me"
  title="PhishDestroy threat report for ppd.cpi.mybluehost.me"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>