الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref 93D043D9

MALICIOUS — CRITICAL

teoutf.sbs — Telegram Impersonation Phishing Report

teoutf[.]sbs

This domain is flagged as an elevated-risk phishing site impersonating Telegram, a messaging platform.

95/100 evidence score · Critical
VirusTotal
17/91
Blocklists
No stored match
التوفر
المحتوى غير متوفر · HTTP 502
Report / Add Evidence Appeal this listing
2026-06-24 08:16 UTCالمحتوى غير متوفر · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 17. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
Jump to section
ملخص التقرير

teoutf.sbs — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Telegram; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 17/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_SPAM; PhishDestroy score 95/100. مسجّل النطاق: NiceNIC.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref 93D043D9

This domain is flagged as an elevated-risk phishing site impersonating Telegram, a messaging platform. Analysis indicates the infrastructure was designed to deceive users into believing they were interacting with legitimate Telegram services, likely through fake login portals or fraudulent account verification pages. The use of Telegram branding in the SSL certificate suggests an attempt to lend credibility to the phishing operation by mimicking the platform's security indicators. Infrastructure analysis reveals the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on June 14, 2026, an unusually future-dated registration that may indicate automated or bulk domain creation. The domain resolves to IP address 216.150.1.1, which has been associated with other malicious activity in prior investigations. Security vendors on VirusTotal flagged the domain with 15/95 detections, while Gridinsoft assigned a trust score of 0/100. The domain appears on one security blocklist and was actively blocked by PhishDestroy. The page title 'Loading...' suggests the site may have employed evasion techniques to delay or obscure its malicious content from automated scanners. Mitigation for this Telegram impersonation threat requires immediate action from network defenders and end-users. Organizations should block the domain at the DNS or proxy level and add the IP address 216.150.1.1 to firewall deny lists. Users who may have interacted with the site should be instructed to reset their Telegram credentials from a secure device and enable multi-factor authentication. Security teams should monitor for unauthorized access attempts or anomalous login activity, particularly from the IP range associated with this phishing infrastructure. Given the future-dated registration, additional domains from the same registrar should be scrutinized for similar patterns.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
17 det.
URLQuery
URLQuery
1 threat alert
ScamAdviser
Scamadviser
80/100
شهادة TLS
منتهية الصلاحية أو غير متحقق منها
العمر
2 mo New
الحالة المرصودة
المحتوى غير متوفر 502
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات13 recorded checks
VirusTotal 17 / 91 URLQuery 1 threat-system alert PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 2 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها Scamadviser 80/100
استخبارات أمن الشبكات Registrar context
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU teoutf.sbs malicious Sinkholed
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer: Telegram

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
17/17
تم استيعاب التهديد
teoutf.sbs تم اكتشافها وإدراجها في قائمة الانتظار لإجراء تحليل شامل
17/06/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
24/06/2026
URLScan Verdict
URLScan returned a malicious verdict · score 100
29/07/2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
17/91 recorded on VirusTotal
28/07/2026
Google Safe Browsing
25/06/2026
Registrar Context: NiceNIC
Separate registrar research is available. Registrar association is contextual and is not scored as an independent detection.
Brand Impersonation
Impersonation of Telegram
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
24/06/2026
Technical Analysis Recorded
يحتوي التقرير على التكنولوجيا المخزنة أو نتائج تحليل الطب الشرعي.
09/08/2026
Site Came Back Online
Domain is responding again — monitoring resumed
06/08/2026
Content Observed Unavailable
سجلت المراقبة استجابة غير متاحة (HTTP 502)؛ لم يتم تحديد السبب بشكل مستقل.
05/08/2026
VT detections increased by 3
+3 new detections (12 → 15): Chong Lua Dao, Forcepoint ThreatSeeker, VIPRE
25/06/2026
Sent Report Recorded
Stored sent-report record for registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, hosting provider, 2 abuse contacts
abuse@vercel.comabuse@nicenic.net
17/06/2026
تم نشر قائمة «DestroyList»
17/06/2026
Content Observed Unavailable
تشير أحدث عمليات التحقق المخزنة إلى أن المحتوى الذي تم الإبلاغ عنه غير متوفر؛ هذا لا يحدد من أو ما سبب التغيير.
05/08/2026
الوقت حتى أول تعذّر للوصول
انقضت ساعات 47 منذ الكشف وحتى أول ملاحظة غير متاحة.

حالة قوائم الحظر العامة

لقطة محفوظة

شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن Telegram · valid for 811 days

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: Telegram report ↗
الخادم / ASN Vercel · AS16509 AMAZON-02 - Amazon.com, Inc., US
IP Context Vercel shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق NiceNIC RU(RU) PhishDestroy Investigation
جهة الإبلاغ عن إساءة الاستخدامabuse@vercel.com, abuse@nicenic.net
البحث في قاعدة بيانات WHOISICANN RDAP لـ teoutf.sbs →
عنوان IP 216.150.1.1 CDN
الموقع الجغرافيUS Walnut, US
الشبكةAS16509 · Amazon.com, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 14/06/2026 (55d · New) Expires 14/06/2027
حالة HTTP502 Error
الوقت حتى أول تعذّر للوصول 47h
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف17/06/2026
DOM Analysisanalyzed 17/06/2026score 88/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://teoutf.sbs/
خوادم الأسماءns3.my-ndns.comns4.my-ndns.com
TLS Fingerprint
TLS Observationvalid from 14/06/2026scanned 17/06/2026
Favicon Hash
Case ID
نطاق SHORTDOT · أدلة عامة .sbs

ShortDot zone evidence

The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.

ShortDot SA · Luxembourg 7 مناطق · أدلة المناطق الكاملة تُحدّث يوميًا افتح مستودع أدلة ShortDot
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.

Latest Classified Outcome 2026-08-05 19:12:49 UTC

Primary outcome Registration hold observed reason: Registry serverHold 95% confidence
Attribution actor class: Registry mechanism: Registry serverHold source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Registry serverHold
Latest HTTP observation غير معروف Origin unreachable Http 5xx 20% 2026-08-09 01:39:03 UTC
RDAP registration Registry serverHold NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientTransferProhibitedserverHoldServertransferprohibited expires 2027-06-14 23:59:59 UTC checked 2026-08-05 19:12:49 UTC
Observed timeline last reachable: 2026-08-05 22:14:37 UTC current episode first observed: 2026-08-06 01:45:45 UTC observed RIP window: 2026-08-05 22:14:37 UTC → 2026-08-06 01:45:45 UTC · 3.52h midpoint estimate ≈ 2026-08-06 00:00:11 UTC · precision high · basis bounded
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

17 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 15 detections
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
كاسبرسكي
LevelBlue
Lionic
SOCRadar
سوفوس
VIPRE
Webroot
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/teoutf.sbs"
  title="PhishDestroy threat report for teoutf.sbs"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.