secure-bots[.]xyz
فحص التصيد والأمان للنطاق secure-bots.xyz
“Telegram: Join Group Chat”
secure-bots.xyz — المحتوى غير متوفر (HTTP 502). نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 2 alerts; PhishDestroy score 83/100. مسجّل النطاق: NameSilo.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
PhishDestroy identifies secure-bots.xyz as an active credential phishing domain designed to steal user login credentials under the guise of a legitimate service. This domain does not appear to impersonate a specific brand but instead uses a generic 'secure bots' theme to lure victims into entering their credentials on a fraudulent login page. The threat involves a drainer kit capable of harvesting credentials and potentially deploying additional malware. Users should exercise extreme caution when encountering this domain, as it poses a direct risk to account security and personal data.
This domain was flagged by PhishDestroy with a VirusTotal detection ratio of 4 out of 95 security vendors, indicating limited but concerning recognition of its malicious nature. secure-bots.xyz was registered on April 28, 2026, through NameSilo, LLC, a domain registrar known for both legitimate and questionable registrations. The domain resolves to IP address 104.21.96.139 and holds a valid SSL certificate issued by Let's Encrypt, which may help it evade browser-based security warnings. As of the latest assessment, this domain has not been blocked by Google Safe Browsing (GSB), and no public blocklist counts are currently available. These technical indicators suggest a relatively new but actively maintained phishing operation.
secure-bots.xyz remains active and poses an elevated risk to unsuspecting users. Immediate actions include blocking this domain at the network level and updating firewall rules to prevent access. Users should avoid interacting with this domain entirely, as any credential submission could result in account compromise or financial loss. While the current threat is elevated, ongoing monitoring is required to assess whether this domain expands its targeting or adopts more sophisticated evasion techniques. Remaining risk is high due to the domain's recent creation, lack of widespread blocking, and active SSL usage, which may deceive users into believing the site is legitimate.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | secure-bots.xyz |
malicious | Sinkholed |
| DNS4EU | secure-bots.xyz |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 3 identified
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com ثقة 100٪Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org ثقة 100٪HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.