presale-sis[.]xyz
“$SIS PRE-SALE”
presale-sis.xyz — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Coinbase; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 4/93 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, G-Data); URLScan malicious verdict; 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of presale-sis.xyz, observed as offline as of July 24 2026, indicates a malicious site that targets Coinbase users through a crypto‑pre‑sale narrative. The domain was registered on February 21 2026 and resolves to IP 104.21.48.1, an address hosted by Cloudflare (AS13335) located in the United States. The TLS certificate presented is identified as “WE1”, suggesting a generic or self‑issued certificate rather than one issued to a legitimate entity. The page title returned from the site is “$SIS PRE‑SALE”, which aligns with the reported scam type of a crypto pre‑sale.
The infrastructure is flagged by multiple external sources: Gridinsoft assigns a trust score of 0 out of 100, two independent security blocklists list the domain, and it is actively blocked by PhishDestroy and ScamSniffer. VirusTotal analysis shows that four of ninety‑three scanned scanners raise detections, reinforcing the malicious classification. The site explicitly impersonates Coinbase, as indicated in the intelligence, and is categorized as a brand‑impersonation crypto scam. No further content was captured because the site is offline, leaving the exact page layout and payload unknown.
Defenders should treat any traffic to presale‑sis.xyz as hostile, block the domain at perimeter firewalls and DNS resolvers, and monitor for related C2 or phishing activity that might reuse the same IP or Cloudflare edge. Continuous re‑scanning is advisable, as the low detection count on VirusTotal may change if the operators reactivate the site or modify its payload. Indicators of compromise include the domain name, the associated IP address, the Cloudflare ASN, and the “$SIS PRE‑SALE” title string, which can be incorporated into intrusion‑detection signatures. Given the elevated risk rating, organizations using Coinbase services should educate users about unsolicited pre‑sale offers and enforce multi‑factor authentication to reduce credential‑theft impact.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب