rippledesktop[.]site
فحص التصيد والأمان للنطاق rippledesktop.site
“Ripple | Global Payments Infrastructure”
rippledesktop.site — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: XRP; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 2/93 (Fortinet, SOCRadar); Spamhaus DBL_PHISH; PhishDestroy score 56/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of rippledesktop.site, registered on 27 February 2026 through NiceNIC International Group Co., Limited, shows infrastructure consistent with a brand‑impersonation campaign targeting the XRP cryptocurrency. The domain resolves to IP 216.198.79.1, an address owned by Amazon.com, Inc. (AS16509) and geolocated to the United States. Both authoritative nameservers, graham.ns.cloudflare.com and rosa.ns.cloudflare.com, are operated by Cloudflare, indicating the use of a commercial DNS provider to hide the true origin of the server. No TLS certificate is presented, meaning connections are unencrypted and susceptible to interception.
VirusTotal has recorded two detections out of 93 scanned security vendors, confirming that at least a minority of scanners flag the site as malicious. The domain appears on a single external blocklist and is actively blocked by PhishDestroy, further corroborating its abusive nature. The HTTP response currently reports an offline status, suggesting the operators have taken the site down, either voluntarily or as a result of takedown actions. The page title returned by the server reads “Ripple | Global Payments Infrastructure,” which aligns with the declared brand target of XRP and the declared scam type of brand impersonation.
Defenders should update any URL filtering or domain‑allow lists to include rippledesktop.site as a malicious indicator, enforce blocklisting in web gateways, and monitor the associated IP address 216.198.79.1 for any new hostnames that may be provisioned on the same infrastructure. Because the domain uses Cloudflare DNS, future iterations may appear under different subdomains or sibling domains without changing the underlying hosting provider. Continuous observation of the ASN AS16509 and the registrar NiceNIC International Group is recommended to detect potential re‑registration attempts.
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 04:18:53 UTC
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260227-E92771 Recipient: abuse@nicenic.net, abuse@radix.email, compliance@icann.org هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب