shibs[.]net
فحص التصيد والأمان للنطاق shibs.net
“Shiba Inu Airdrop”
shibs.net — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Coinbase; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 1/93 (Gridinsoft); PhishDestroy score 56/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
Analysis on shibs.net shows a recent cryptocurrency impersonation campaign targeting Coinbase users. The domain was registered on July 17, 2025 through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to the IPv4 address 92.113.16.74, which is hosted in Germany under AS47583 owned by Hostinger International Limited. The TLS certificate presented is a ZeroSSL RSA Domain Secure Site CA certificate, indicating a publicly issued but inexpensive certificate often used by malicious operators. The page title returned during the last crawl was "Shiba Inu Airdrop", a phrasing commonly employed to lure victims with promises of free token distribution. The campaign is classified as a crypto scam and specifically impersonates the Coinbase brand, as indicated in the provided intelligence.
The domain appears on one security blocklist and is listed by PhishDestroy as blocked. VirusTotal records show that one of ninety‑three security vendors flagged the domain, confirming at least one independent detection. Gridinsoft assigned a trust score of 0 out of 100, reinforcing the malicious assessment. No additional content or login forms have been captured, so the exact page layout and credential‑harvesting mechanisms remain unknown.
Defenders should immediately deny any network traffic to 92.113.16.74 and add shibs.net to DNS‑based blocklists. Monitoring for newly registered domains that resolve to the same hosting provider or that use similar "Airdrop Scam" kits is advised. Given the impersonation of Coinbase, security teams should update email filters for phishing attempts referencing "Shiba Inu Airdrop" or similar cryptocurrency giveaways. Although the site is currently offline, the infrastructure may be reused, so continuous threat‑intel feeds should be consulted for re‑appearance.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 04:20:36 UTC
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.