الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 5. قوائم الحظر العامة التي تبلغ عن تطابق: 1. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@alibaba-inc.com. The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
1 month
Reports sent
1
Latest case ID
PD-20260712-D84F86
Current status
Observed active at latest stored check
أمن المجال وذكاء التهديدات

tnsq7j39e6[.]skywork[.]website

“Skywork︱The Originator of AI Workspace Agents”

حكم التهديد حرجة 71/100 درجة الأدلة
التوفر لم يتم التحقق منها لم يتم التحقق من إمكانية الوصول الحالية
اكتشافات VirusTotal: 5/91 تطابقات القائمة السوداء المخزنة: 1 URLQuery threat systems: 1 alert نوع الاحتيال: Brand Impersonation
10/07/2026 1 Report Sent
ملخص التقرير

tnsq7j39e6.skywork.website — لم يتم التحقق منها. نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 1 alert; 1 external blocklist match (ScamSniffer); PhishDestroy score 71/100. مسجّل النطاق: Alibaba Cloud Computing.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
7870F358
الدرجة
71/100

This domain, tnsq7j39e6.skywork.website, is identified as a high-risk phishing infrastructure specifically designed to impersonate Stripe payment portals. Analysis indicates the site employs fraudulent checkout forms to harvest financial credentials, including credit card details and login information. The use of Stripe’s legitimate payment processing technology, combined with tracking tools like Google Analytics and Facebook Pixel, suggests an attempt to create a convincing replica of authentic payment gateways, increasing the likelihood of successful credential theft. Evidence supporting this assessment includes detection by 2 out of 95 security vendors on VirusTotal, a relatively low but notable blocklist count that may indicate early-stage deployment. The domain was registered on August 05, 2025, through Alibaba Cloud Computing Ltd. d/b/a HiChina, a registrar frequently associated with newly created malicious domains. Infrastructure analysis reveals the domain resolves to the IP address 47.85.109.221, and it employs an SSL certificate issued by DigiCert Inc, which may lend a false sense of legitimacy to unsuspecting users. The presence of HTTP/3 and modern web frameworks like Vue.js further suggests an effort to evade traditional detection mechanisms. Users who have visited tnsq7j39e6.skywork.website or entered credentials on the site should immediately revoke any submitted information, particularly financial details. It is recommended to monitor associated accounts for unauthorized transactions and enable multi-factor authentication where available. System scans using updated security tools should be conducted to detect potential malware or persistent threats. Organizations should block the domain and its resolving IP at the network level to prevent further exposure. Given the domain’s recent creation and active status, heightened vigilance is advised for any communications or transactions linked to this infrastructure.

VirusTotal
VirusTotal
5 det.
URLQuery
URLQuery
1 threat alert
شهادة TLS
DigiCert Inc 26d
العمر
1 yr
الحالة المرصودة
لم يتم التحقق منها
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات VirusTotal 5 / 91 URLQuery 1 threat-system alert PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 26d WHOIS 12 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
Hagezi Threat Feed tnsq7j39e6.skywork.website malicious Sinkholed

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
12/13
Sent Report Recorded
Stored sent-report record for registrar Alibaba Cloud Computing Ltd. d/b/a HiChina (www.net.cn), hosting provider, 3 abuse contacts
abuse@alibaba-inc.comdomainabuse@service.aliyun.comintl-abuse@list.alibaba-inc.com
12/07/2026

حالة قوائم الحظر العامة

لقطة محفوظة

عنوان الصفحة
Skywork︱The Originator of AI Workspace Agents
شهادة TLS
Valid transport encryption · صادرة عن DigiCert Inc · valid for 26 days

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN AmazonS3 · AS45102 ALIBABA-CN-NET - Alibaba (US) Technology Co., Ltd., CN
سمعة عنوان IP abuse score 0/100 0 reports checked 09/08/2026
Registrar (base domain) Alibaba Cloud Computing
عنوان IP 47.253.88.145 US
الموقع الجغرافيUS Virginia Beach, US
الشبكةAS45102 · Alibaba (US) Technology Co., Ltd.
Registration (base domain)skywork.website · تم إنشاؤه 05/08/2025 Expires 05/08/2027
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف10/07/2026
DOM Analysisanalyzed 10/07/2026score 71/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://tnsq7j39e6.skywork.website/
خوادم الأسماءvip3.alidns.comvip4.alidns.com
TLS Fingerprint
TLS Observationvalid from 06/08/2025scanned 10/07/2026
TLS SAN Domainsskywork.website
Case ID
ICANN OVERSIGHT Registration: skywork.website

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain skywork.website behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
التقنيات · 8 identified
Vue.js
JavaScript frameworks

Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.

vuejs.org ثقة 100٪
Stripe
Payment processors

Stripe offers online payment processing for internet businesses as well as fraud prevention, invoicing and subscription management.

stripe.com ثقة 100٪
Microsoft Advertising
Advertising

Microsoft Advertising is an online advertising platform developed by Microsoft.

ads.microsoft.com ثقة 100٪
Linkedin Insight Tag
Analytics

LinkedIn Insight Tag is a lightweight JavaScript tag that powers conversion tracking, website audiences, and website demographics.

business.linkedin.com ثقة 100٪
Google Tag Manager
Tag managers

Google Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.

www.google.com ثقة 100٪
Google Analytics
Analytics

Google Analytics is a free web analytics service that tracks and reports website traffic.

google.com ثقة 100٪
Facebook Pixel
Analytics

Facebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.

facebook.com ثقة 100٪
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org ثقة 100٪
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

5 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 2 detections
alphaMountain.ai
CRDF
Forcepoint ThreatSeeker
Gridinsoft
SOCRadar

الأدلة والتقارير الخارجية

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260712-D84F86 Recipient: abuse@alibaba-inc.com
Page title stored with report: Korboi — Digital Services Catalog
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 23.9 KB
Blocklist hits included with submission: ScamSniffer
نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/tnsq7j39e6.skywork.website"
  title="PhishDestroy threat report for tnsq7j39e6.skywork.website"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.