الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 15. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

raven[.]cyberfish[.]io

“404 - Quick Tip | Cofense”

حكم التهديد حرجة 95/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 15/94 نوع الاحتيال: Crypto Scam
24/03/2026

ملخص الأدلة

حرج
Evidence score
95/100

Analysis of the domain raven.cyberfish.io, registered on March 23, 2026, through MarkMonitor Inc., reveals infrastructure associated with a crypto scam impersonating Cofense. The domain resolves to IP 52.204.246.179, hosted on AWS EC2 in the US (us-east-1 region), and employs Let's Encrypt SSL certification. At the time of assessment, the domain returned an HTTP 404 status with the page title '404 - Quick Tip | Cofense,' suggesting an attempt to mimic Cofense, a known security awareness training provider. This title alignment, combined with the scam type classification as a 'Crypto Scam,' indicates the domain was likely designed to deceive users into engaging with fraudulent cryptocurrency schemes under the guise of a legitimate brand.

The domain appears on one security blocklist and is flagged by 15 of 94 security vendors on VirusTotal, reflecting elevated risk. It was blocked by PhishDestroy and is currently offline. Infrastructure analysis shows the use of AWS nameservers (ns-299.awsdns-37.com, ns-1565.awsdns-03.co.uk, ns-892.awsdns-47.net) and HSTS implementation, which may have been leveraged to lend an appearance of legitimacy. The domain's creation date and hosting on a major cloud provider align with patterns observed in short-lived phishing campaigns, though no specific phishing kit or additional technical artifacts have been confirmed.

Defenders should treat this domain as malicious and prioritize blocking it at the DNS and network levels. The presence of HSTS and a valid SSL certificate underscores the need for layered defenses, including endpoint protection and user awareness training focused on crypto-related scams. While the domain is currently offline, historical resolutions to 52.204.246.179 should be monitored for re-emergence or related infrastructure reuse. Further investigation into the registrar's abuse response and AWS hosting logs may provide additional context on the campaign's scope and operators.

VirusTotal
VirusTotal
15 det.
DNS Security
6/14
شهادة TLS
Let's Encrypt
العمر
5 mo
الحالة المرصودة
المحتوى غير متوفر HTTP 404
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 15 / 94 URLQuery لم يتم التحقق منها PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 6/14 TLS valid certificate, 80d WHOIS 5 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
DNS Provider Blocks 6 / 14
Adguard Default Adguard Family Controld Adblock Controld Family Controld Malware Quad9 Secure

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
13/14

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. VirusTotal

    0 ← 13

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN AS14618 Amazon.com, Inc.
سمعة عنوان IP IP abuse confidence 0/100 0 reports checked 14/07/2026
Registrar (base domain) MarkMonitor
عنوان IP 52.204.246.179 US
الموقع الجغرافيUS Ashburn, US
الشبكةAS14618 · AWS EC2 (us-east-1)
Registration (base domain)cyberfish.io · تم إنشاؤه 23/03/2026 (139d)
حالة HTTP404 Not Found
الوقت حتى أول تعذّر للوصول 29h
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف24/03/2026
Submitted URLhttp://raven.cyberfish.io/s/63BZGFSVBWSFCDX7Y9/584dd8/90eab167-7429-489f-99f6-ce86e8d0d81a
خوادم الأسماءns-1437.awsdns-51.org
بصمة TLS
رصد TLSصالح منذ 14/05/2026فُحص في 27/07/2026
الأسماء البديلة لموضوع TLScyberfish.io
Favicon Hash
عنوان الصفحة
404 - Quick Tip | Cofense
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 80 days
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

15 / قام موردو الأمان 94 بوضع علامة على هذا المجال
View on VT
Last analyzed
ADMINUSLabs
Cluster25
CRDF
CyRadar
DNS8
Emsisoft
Fortinet
G-Data
Gridinsoft
LevelBlue
Lionic
SOCRadar
سوفوس
URLQuery
Webroot
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of raven.cyberfish.io · checked Mar 24, 2026

94
Good
Performance
FCP
0.76s
First Contentful Paint
LCP
1.8s
Largest Contentful Paint
CLS
0.142
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
1.05s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
تحليل إعدادات الموقع
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/raven.cyberfish.io"
  title="PhishDestroy threat report for raven.cyberfish.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>