الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref A32480B1

MALICIOUS — CRITICAL

stonexotcs.cc Alert — Crypto Drainer Phishing Detected

stonexotcs[.]cc

PhishDestroy identifies stonexotcs.cc as an active crypto drainer phishing domain operating at elevated risk.

80/100 evidence score · Critical
VirusTotal
6/94
Blocklists
2 · MetaMask, SEAL
التوفر
المحتوى غير متوفر · HTTP 502
Report / Add Evidence Appeal this listing
2026-04-17 13:22 UTCالمحتوى غير متوفر · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 6. قوائم الحظر العامة التي تبلغ عن تطابق: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
Jump to section
ملخص التقرير

stonexotcs.cc — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Google; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 6/94 (ADMINUSLabs, alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Google Safebrowsing); URLQuery 1 det.; Google Safe Browsing flagged; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 80/100. مسجّل النطاق: Gname.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref A32480B1

PhishDestroy identifies stonexotcs.cc as an active crypto drainer phishing domain operating at elevated risk. This domain is engineered to siphon cryptocurrency assets by deceiving users into connecting wallets or entering seed phrases on fraudulent landing pages. It is not a generic phishing attempt but a targeted crypto theft operation designed to exploit trust in blockchain interactions. This domain was flagged by PhishDestroy with a risk level of elevated and classified under generic_phishing due to its active role in cryptocurrency theft campaigns. stonexotcs.cc was registered on March 23, 2026 through Gname.com Pte. Ltd., resolving to IP address 172.67.170.157. The domain holds a Let's Encrypt SSL certificate, which increases its perceived legitimacy. VirusTotal analysis shows only 2 out of 95 security vendors currently detect malicious content, while Google Safe Browsing has labeled the site under the SOCIAL_ENGINEERING category, confirming its deceptive intent toward unsuspecting users. Crypto drainer domains like stonexotcs.cc typically mimic legitimate platforms such as exchanges, wallets, or DeFi protocols. Users are strongly advised to never connect wallets or enter credentials on untrusted domains. Always verify the domain URL against PhishDestroy’s threat intelligence database before interacting with any crypto-related website. If exposure occurs, immediately revoke wallet connections, transfer assets to cold storage, and report the domain to relevant authorities to prevent further exploitation.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
6 det.
URLQuery
URLQuery
1 det.
DNS Security
1/12
شهادة TLS
Let's Encrypt
العمر
4 mo
الحالة المرصودة
المحتوى غير متوفر 502
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات12 recorded checks
VirusTotal 6 / 94 URLQuery 1 det. PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 1/12 TLS valid certificate, 64d WHOIS 4 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
DNS Provider Blocks 1 / 12
Brand Ton

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
16/16
تم استيعاب التهديد
stonexotcs.cc تم اكتشافها وإدراجها في قائمة الانتظار لإجراء تحليل شامل
17/04/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
URLScan Verdict
اكتمل تحليل URLScan؛ لا تغير نتيجة التقاط الويب هذه حكم تهديد الصفحة · score 0
29/07/2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
Web Archive
Preserved in آلة الزمن — historical evidence archived
18/04/2026
VirusTotal
6/94 recorded on VirusTotal
14/05/2026
Google Safe Browsing
17/04/2026
الكشف عن قوائم الحظر
موجود في 2 blocklists: MetaMask, SEAL
09/08/2026
DNS Security Blocks
Blocked by 1 of 12 checked DNS providers: Brand ton
Brand Impersonation
Impersonation of Google
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
Technical Analysis Recorded
يحتوي التقرير على التكنولوجيا المخزنة أو نتائج تحليل الطب الشرعي.
09/08/2026
Sent Report Recorded
Stored sent-report record for registrar Gname.com Pte. Ltd., hosting provider, 1 abuse contact
complaint@gname.com
17/04/2026
تم نشر قائمة «DestroyList»
17/04/2026
Content Observed Unavailable
تشير أحدث عمليات التحقق المخزنة إلى أن المحتوى الذي تم الإبلاغ عنه غير متوفر؛ هذا لا يحدد من أو ما سبب التغيير.
23/04/2026
الوقت حتى أول تعذّر للوصول
انقضت ساعات 132 منذ الكشف وحتى أول ملاحظة غير متاحة.

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
Google Safe Browsing تم وضع علامة عليها Social engineering checked 17/04/2026
الخادم / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق Gname (HK,CN)
جهة الإبلاغ عن إساءة الاستخدامcomplaint@gname.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ stonexotcs.cc →
عنوان IP 172.67.170.157 CDN
الموقع الجغرافيCA Toronto, CA
الشبكةAS13335 · Cloudflare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 17/04/2026 (113d)
حالة HTTP502 Error
الوقت حتى أول تعذّر للوصول 6 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف17/04/2026
DOM Analysisanalyzed 29/07/2026score 80/1001 brand signal
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://stonexotcs.cc/
خوادم الأسماءviddy.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 23/03/2026scanned 17/04/2026
Case ID
عنوان الصفحة
StoneX
Impersonates
Bank Of America
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 64 days
التقنيات · 4 identified
V
Vue.js
JavaScript frameworks

Progressive JavaScript framework for building user interfaces.

Cloudflare Browser Insights
Analytics RUM

Performance monitoring tool that measures website speed from real users.

www.cloudflare.com
Cloudflare
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

6 / قام موردو الأمان 94 بوضع علامة على هذا المجال
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
CRDF
Forcepoint ThreatSeeker
Google Safebrowsing
Gridinsoft

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of stonexotcs.cc · checked Apr 17, 2026

56
Needs Work
Performance
FCP
5.75s
First Contentful Paint
LCP
9.42s
Largest Contentful Paint
CLS
0.067
Cumulative Layout Shift
TBT
59ms
Total Blocking Time
SI
8.53s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/stonexotcs.cc"
  title="PhishDestroy threat report for stonexotcs.cc"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>