prelix-klavor-biz-hendix-grentor-sp7ct12[.]pages[.]dev
“Suspected phishing site | Cloudflare”
prelix-klavor-biz-hendix-grentor-sp7ct12.pages.dev — المحتوى غير متوفر. نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 13/94 (Criminal IP, BitDefender, CyRadar, ESET, Emsisoft); PhishDestroy score 99/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies prelix-klavor-biz-hendix-grentor-sp7ct12.pages.dev as a live crypto drainer phishing domain designed to trick users into connecting cryptocurrency wallets and authorize malicious transactions. The site impersonates legitimate crypto services by leveraging Cloudflare Pages hosting and a Google Trust Services SSL certificate to appear authentic. Threat actors utilize randomized subdomains (prelix-klavor-biz-hendix-grentor-) with appended tokens (sp7ct12) to evade detection and scale operations across multiple fraudulent projects. Analysis shows the domain resolves to IP 172.66.47.195 and has been active in the threat landscape since its creation through Cloudflare, Inc., which serves as both hosting provider and domain registrar to obscure true ownership. This domain poses an elevated risk due to its confirmed malicious status across multiple security platforms. PhishDestroy’s threat intelligence confirms that 11 out of 95 VirusTotal security vendors classify this domain as malicious, while it appears on 1 public blocklist and is directly blocked by OpenPhish, a leading phishing intelligence feed. The use of Cloudflare Pages for hosting enables rapid deployment and takedown evasion, while the Google Trust Services SSL certificate increases user trust, making it more likely that victims will interact with the page and connect their wallets. The combination of high-risk infrastructure, low detection variability across vendors, and active blocking by reputable feeds confirms this as a targeted crypto drainer operation. Users who have visited this domain should immediately disconnect their cryptocurrency wallets and revoke any unauthorized permissions granted through wallet interfaces such as MetaMask or Phantom. Run a full antivirus scan on any device used to access the site, and consider generating a new wallet address and moving funds to a cold storage solution if unauthorized transactions are suspected. PhishDestroy recommends checking the domain status on PhishDestroy’s real-time database before engaging with any crypto-related service, especially those involving wallet connections or token transfers. Never approve transactions from unknown websites, and verify URLs through official project channels. Educate team members and family about this threat, as crypto drainers often impersonate popular NFT marketplaces, DeFi platforms, or airdrop campaigns.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of prelix-klavor-biz-hendix-grentor-sp7ct12.pages.dev · checked Apr 10, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب