pub-2850cd5d83b9406498615dc0f50afc0d[.]r2[.]dev
“Not Found”
pub-2850cd5d83b9406498615dc0f50afc0d.r2.dev — لم يتم التحقق منها. انتحال العلامة التجارية: Microsoft; نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 12/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); URLQuery 4 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 88/100. مسجّل النطاق: Cloudflare R2.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies pub-2850cd5d83b9406498615dc0f50afc0d.r2.dev as a high-risk crypto drainer domain designed to steal cryptocurrency from unsuspecting users. This site poses an immediate financial threat by tricking visitors into connecting crypto wallets or entering private keys, allowing attackers to drain funds directly. The domain’s behavior aligns with known crypto drainer tactics, where victims are lured via fake giveaways, fraudulent investment opportunities, or impersonated services to authorize malicious transactions. This domain was flagged by 15 out of 95 VirusTotal security vendors, placed on 3 separate blocklists (PhishingArmy, PhishingDB, OISD), and resolves to IP address 104.18.50.34. The domain’s SSL certificate was issued by Let’s Encrypt, and it remains active despite widespread detection. Security reports indicate this domain is part of a larger infrastructure targeting cryptocurrency holders, with no legitimate use case identified. If you visited pub-2850cd5d83b9406498615dc0f50afc0d.r2.dev, immediately disconnect your wallet and revoke any unauthorized permissions. Do not enter private keys or approve transactions. Use a trusted tool like PhishDestroy to scan for associated malware or compromised accounts. Report the domain to your wallet provider or relevant authorities to prevent further abuse. Stay vigilant—crypto drainers evolve rapidly, and verification is critical before any interaction.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | pub-2850cd5d83b9406498615dc0f50afc0d.r2.dev |
malicious | Sinkholed |
| Cloudflare DNS | pub-2850cd5d83b9406498615dc0f50afc0d.r2.dev |
malicious | Sinkholed |
| DNS4EU | pub-2850cd5d83b9406498615dc0f50afc0d.r2.dev |
malicious | Sinkholed |
| OpenDNS | pub-2850cd5d83b9406498615dc0f50afc0d.r2.dev |
phishing | Phishing Block |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comتحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of pub-2850cd5d83b9406498615dc0f50afc0d.r2.dev · checked Apr 12, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب