tia[.]beefyhubs[.]life
“Google”
tia.beefyhubs.life — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Google; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 13/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 89/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, tia.beefyhubs.life, is identified as a brand_impersonation threat targeting Gmail users. Analysis indicates the site presents a fraudulent Google login interface, designed to harvest credentials, authentication tokens, and potentially enable account takeover. The page title explicitly mimics the legitimate service, displaying 'Google' to deceive users into entering sensitive information. No associated drainer kit or secondary payload delivery was observed in preliminary analysis, though credential harvesting remains the primary objective. Technical indicators reveal the domain was registered through Cloudflare, Inc., a registrar frequently utilized for both legitimate and malicious infrastructure. It resolves to the IP address 142.250.186.68, geolocated in Germany under AS15169 (Google LLC), suggesting potential IP spoofing or misconfiguration to evade detection. At the time of analysis, VirusTotal detection rates stood at 13 out of 95 security vendors, while the domain appeared on a single security blocklist. No SSL certificate was present, increasing the likelihood of interception or man-in-the-middle attacks. Creation date metadata was unavailable, limiting temporal attribution, though the domain's rapid takedown suggests reactive mitigation. The domain is currently offline, likely following detection and reporting by security entities such as PhishDestroy. While the immediate threat has been neutralized, residual risk persists due to potential credential reuse by affected users. Infrastructure analysis reveals the use of Cloudflare registrars and Google-hosted IPs, a tactic observed in other phishing campaigns to blend with legitimate traffic. Users are advised to revoke any sessions initiated on this domain, enable multi-factor authentication, and monitor accounts for unauthorized activity. Organizations should update blocklists to include tia.beefyhubs.life and its resolved IP, while security teams should investigate potential lateral movement from harvested credentials.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: beefyhubs.life
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain beefyhubs.life behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب