الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 6. قوائم الحظر العامة التي تبلغ عن تطابق: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

proposals-usdai[.]xyz

حكم التهديد حرجة 70/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 6/94 تطابقات القائمة السوداء المخزنة: 2 نوع الاحتيال: Fake Exchange
07/04/2026 1 Report Sent CDN
ملخص التقرير

proposals-usdai.xyz — المحتوى غير متوفر. نوع الاحتيال: Fake Exchange. ملخص الأدلة: VirusTotal 6/94 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 70/100. مسجّل النطاق: PDR.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
A5D238FA
الدرجة
70/100

This domain, proposals-usdai.xyz, operates as a crypto drainer phishing site designed to steal digital wallet credentials and drain cryptocurrency funds from victims. Analysis indicates the site mimics legitimate decentralized finance (DeFi) platforms, tricking users into connecting wallets or entering seed phrases under false pretenses, such as claiming to offer token swaps or airdrops. Once credentials are entered, the site executes unauthorized transactions, transferring assets to attacker-controlled wallets without user consent. The threat primarily targets users of popular wallets and DeFi services, exploiting trust in branded interfaces and urgency-driven offers. Infrastructure analysis reveals multiple red flags confirming the malicious nature of this domain. The domain was registered on April 7, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently associated with phishing and fraudulent domains. At the time of assessment, the domain resolved to the IP address 188.114.97.3 and was flagged by 6 out of 95 security vendors on VirusTotal, including detections for phishing and malicious activity. Additionally, the domain appeared on three security blocklists and was proactively blocked by multiple wallet security providers. A trust score of 0/100 from Gridinsoft further corroborates the high-risk classification of this infrastructure. Users who visited proposals-usdai.xyz or interacted with its content should take immediate action to mitigate potential losses. First, disconnect any wallets linked to the site by revoking permissions via the wallet’s connected apps or dApp browser settings. Next, transfer remaining funds to a new, secure wallet using a trusted device, as the original wallet may be compromised. Monitor transaction histories for unauthorized activity and report any suspicious transactions to the wallet provider or relevant blockchain explorers. If seed phrases or private keys were entered, consider the wallet fully compromised and avoid using it for future transactions. Finally, scan the device used to access the site for malware, as phishing pages may deploy additional payloads. Users are advised to enable multi-factor authentication on all accounts and verify domain authenticity before interacting with any financial or DeFi platforms.

VirusTotal
VirusTotal
6 det.
شهادة TLS
منتهية الصلاحية أو غير متحقق منها
العمر
4 mo
الحالة المرصودة
المحتوى غير متوفر
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات VirusTotal 6 / 94 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references رادار CF no data URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 12 تم الفحص — لا يوجد حظر TLS منتهية الصلاحية أو غير متحقق منها WHOIS 4 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer:

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
13/13
Sent Report Recorded
Stored sent-report record for registrar PDR Ltd. d/b/a PublicDomainRegistry.com, hosting provider, 3 abuse contacts
abuse@publicdomainregistry.comabuse-contact@publicdomainregistry.comcox197517@ycyfugihih.cfd
07/04/2026

حالة قوائم الحظر العامة

لقطة محفوظة

شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن Let's Encrypt / E7

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق PDR US(US)
عنوان IP 188.114.97.3 CDN
الموقع الجغرافيCA Toronto, CA
الشبكةAS13335 · CloudFlare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 07/04/2026 (133d)
الوقت حتى أول تعذّر للوصول 20h
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف07/04/2026
DOM Analysisanalyzed 29/07/2026score 70/100
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://proposals-usdai.xyz/
خوادم الأسماءalexia.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 06/04/2026scanned 08/04/2026
Case ID
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.

الاستخبارات الجنائية الرقمية

External Scripts 1
https://performance.radar.cloudflare.com/beacon.js
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

6 / قام موردو الأمان 94 بوضع علامة على هذا المجال
View on VT
Last analyzed
alphaMountain.ai
CyRadar
Forcepoint ThreatSeeker
Gridinsoft
SOCRadar
Webroot
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of proposals-usdai.xyz · checked Jun 26, 2026

87
Needs Work
Performance
FCP
0.76s
First Contentful Paint
LCP
2.33s
Largest Contentful Paint
CLS
0.001
Cumulative Layout Shift
TBT
445ms
Total Blocking Time
SI
1.43s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

الأدلة والتقارير الخارجية

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260407-1D7252 Recipient: abuse@publicdomainregistry.com
Page title stored with report: Just a moment...
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 1,452.3 KB
نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/proposals-usdai.xyz"
  title="PhishDestroy threat report for proposals-usdai.xyz"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.