terrachainresolver[.]xyz
“TerraCR (TCR) - Dapps Troubleshooting Services”
terrachainresolver.xyz — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Ethereum; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 2/93 (alphaMountain.ai, Forcepoint ThreatSeeker); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of terrachainresolver.xyz indicates a malicious infrastructure designed to impersonate the Ethereum brand. The domain was registered on February 21, 2026 and is currently offline, preventing live content retrieval. Historical HTTP responses show the site previously served a page titled “TerraCR (TCR) - Dapps Troubleshooting Services,” which aligns with the declared crypto‑scam classification. The domain resolves to the IP address 104.21.93.193, an address owned by Cloudflare, Inc. in Canada, a common hosting provider for fast‑flux and abuse‑hosting operations.
The SSL certificate presented is identified as “WE1,” suggesting a self‑issued or low‑trust certificate, a pattern often observed in fraudulent sites. Reputation checks reveal that two of ninety‑three VirusTotal scanners flagged the domain, and the domain appears on four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—reinforcing the notion of malicious intent. No additional intelligence such as OTX tags, Safe Browsing status, or registrar details is available in the current dataset. The lack of a live endpoint limits verification of the exact phishing payload, but the combination of brand impersonation, a misleading page title, and multiple security vendor alerts provides sufficient evidence to classify the domain as a crypto‑related impersonation threat.
Defenders should add the domain and its resolving IP to deny‑list rules across perimeter firewalls and DNS filtering solutions. Because the IP belongs to a shared Cloudflare pool, broader network‑level blocking may impact legitimate services; therefore, threat‑intel feeds that correlate the specific IP with the domain should be consulted before blanket IP blocks. Continuous monitoring for re‑registration or resurrection of the domain is advised, as actors frequently recycle infrastructure.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب