الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 8. قوائم الحظر العامة التي تبلغ عن تطابق: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

redpay[.]icu

“Download RedotPay APP”

حكم التهديد حرجة 74/100 درجة الأدلة
التوفر خطأ في الخادم آخر استجابة مخزنة كانت غير حاسمة
اكتشافات VirusTotal: 8/91 Spamhaus DBL: DBL_PHISH تطابقات القائمة السوداء المخزنة: 2
06/07/2026 CDN

ملخص الأدلة

حرج
Evidence score
74/100

This domain, redpay.icu, poses a high-risk phishing threat by impersonating the legitimate RedotPay mobile application platform. Analysis indicates the site is designed to deceive users into downloading a fraudulent application, likely containing malicious payloads such as credential harvesters, remote access trojans, or financial data exfiltration tools. The page title explicitly reads 'Download RedotPay APP,' suggesting a direct attempt to mimic official distribution channels for mobile payment applications, a common tactic in targeted financial fraud campaigns. Infrastructure analysis reveals the domain was registered on July 05, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. The domain resolves to the IP address 188.114.96.3, which may host additional malicious infrastructure. As of the latest assessment, the domain is flagged by 5 out of 95 security vendors on VirusTotal, indicating early detection but limited widespread blocklisting. The domain remains active, increasing the likelihood of continued exploitation attempts against unsuspecting users. Users who have visited redpay.icu or interacted with its content are advised to take immediate remediation steps. Any downloaded files should be treated as compromised and deleted without execution. Devices used to access the domain should undergo a full antivirus scan using updated detection signatures. Credentials entered on the site or related applications must be reset from a secure device, and multi-factor authentication should be enabled where available. Financial institutions should be notified if payment details were submitted, and transaction monitoring should be heightened for signs of unauthorized activity. Organizations are encouraged to block the domain and associated IP at the network perimeter to prevent further exposure.

VirusTotal
VirusTotal
8 det.
شهادة TLS
Google Trust Services / WE1
العمر
1 mo New
الحالة المرصودة
خطأ في الخادم HTTP 502
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 8 / 91 URLQuery لم يتم التحقق منها PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 54d WHOIS 1 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكاتRegistrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
11/13

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026

٨ مصادر خارجية مراقبة لا تطابق

أدلة النتيجة المحفوظة

النتيجة وإسناد الإزالة

النتيجة
dns_inactive
السبب
dns_nxdomain
درجة الثقة
80%
أول رصد
أحدث رصد

وقت التعطل التقديري

الوقت حتى تعذر الوصول: 0 h

SHA-256 للدليل d0b7046e8c2f

المخطط الزمني للاكتشاف

  1. التوفر

    أول قيمة محفوظة: DNS غير نشط

    f93a11f87e4d
  2. التوفر

    DNS غير نشط ← غير معروف

    79bdced6e023
  3. التوفر

    غير معروف ← DNS غير نشط

    cac6a8a9964e
  4. التوفر

    DNS غير نشط ← محتجز

    4bc092615ee5
  5. التوفر

    محتجز ← DNS غير نشط

    f52d526b76a1
  6. التوفر

    DNS غير نشط ← غير معروف

    03a61f34945c
  7. التوفر

    غير معروف ← محتجز

    15aaf08be37f
  8. التوفر

    محتجز ← غير معروف

    72d4798de9ab
  9. التوفر

    غير معروف ← DNS غير نشط

    6dfe9145995c
  10. التوفر

    DNS غير نشط ← غير معروف

    4b4842acb7e9
عرض الكل (1)
  1. التوفر

    غير معروف ← DNS غير نشط

    d0b7046e8c2f

بلاغات المجتمع

لم يبلّغ عنه أي عضو في المجتمع؛ شوهد أول مرة في 06/07/2026

عناوين URL الفريدة المبلغ عنها
1

لقطة محفوظة

عنوان الصفحة
Download RedotPay APP
شهادة TLS
Valid transport encryption · صادرة عن Google Trust Services / WE1 · valid for 54 days

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN cloudflare · AS13335 CLOUDFLARENET - Cloudflare, Inc., US
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق NiceNIC RU(RU) PhishDestroy Investigation
جهة الإبلاغ عن إساءة الاستخدامabuse@nicenic.net
البحث في قاعدة بيانات WHOISICANN RDAP لـ redpay.icu →
عنوان IP 104.21.92.27 CDN
الموقع الجغرافيUS San Francisco, US
الشبكةAS13335 · Cloudflare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 05/07/2026 (35d · New) Expires 05/07/2027
حالة HTTP502 Error
Elapsed Since First Report 3h
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: خطأ في الخادم.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف06/07/2026
DOM Analysisanalyzed 06/07/2026DOM analysis score 0/100
Submitted URLhttp://redpay.icu/
خوادم الأسماءbetty.ns.cloudflare.complato.ns.cloudflare.com
بصمة TLS
رصد TLSصالح منذ 05/07/2026فُحص في 06/07/2026
نطاق SHORTDOT · أدلة عامة .icu

ShortDot zone evidence

The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.

ShortDot SA · Luxembourg 7 مناطق · أدلة المناطق الكاملة تُحدّث يوميًا افتح مستودع أدلة ShortDot
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.

التقنيات

حُدّدت ٣ تقنيات عالية الثقة

Vue.js Cloudflare HTTP/3
Cloudflare Radar
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

8 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed
alphaMountain.ai
Ermes
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
LevelBlue
سوفوس

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/redpay.icu"
  title="PhishDestroy threat report for redpay.icu"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.