الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 5. قوائم الحظر العامة التي تبلغ عن تطابق: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

transfer-tws[.]ink

“Crypto Cards”

حكم التهديد حرجة 85/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 5/91 تطابقات القائمة السوداء المخزنة: 2 URLQuery threat systems: 3 alerts
23/07/2026 1 Report Sent

ملخص الأدلة

حرج
Evidence score
85/100

Analysis of transfer-tws.ink as of July 23, 2026, indicates this domain is part of active phishing infrastructure targeting financial or trading platforms. The domain resolves to IP address 54.39.106.37 and is currently flagged on at least one security blocklist, including PhishDestroy. While VirusTotal scans from 95 vendors show no detections at the time of this report, this absence does not confirm safety, as phishing domains often evade initial detection. The domain remains operational, returning an HTTP 200 status, suggesting the phishing page is live. Infrastructure details reveal the domain uses Let's Encrypt SSL certificate YR2, a common choice for both legitimate and malicious sites due to its free and automated issuance.

Nameservers are hosted on pdns1.registrar-servers.com and pdns2.registrar-servers.com, a configuration frequently observed in phishing campaigns leveraging bulk domain registration services. No specific brand or kit has been confirmed in the available data, and the exact content of the site has not been analyzed. The domain's naming convention, including 'transfer' and 'tws,' suggests it may impersonate trading, brokerage, or banking services, but this remains unconfirmed without further evidence. Defenders should treat transfer-tws.ink as high-risk until additional analysis confirms its intent.

Network-level blocking is recommended based on the current blocklist presence and active resolution. Organizations should monitor for connections to 54.39.106.37 and investigate any user reports of interaction with the domain. Further investigation is required to determine the targeted brand, phishing kit, or payload. No evidence currently links this domain to advanced persistent threats or nation-state actors.

لقطة الأدلة المرسلة

أُرسل
سجلات الدفتر
1
معرّف القضية
PD-20260723-740FA8
عنوان الصفحة الملتقطة
Crypto Cards
ملف PDF
دليل PDF
النص الكامل للدليل
Policy Violations:
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
VirusTotal
VirusTotal
5 det.
URLQuery
URLQuery
3 threat alerts
شهادة TLS
Let's Encrypt
الحالة المرصودة
المحتوى غير متوفر HTTP 502
PhishDestroy
قائمة الإتلاف
مدرج
Reports Sent
1

Data Coverage

VirusTotal 5 / 91 URLQuery 3 threat-system alerts PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 81d WHOIS not parsed لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
Hagezi Threat Feed tw-coin.org malicious Sinkholed
DNS4EU tw-coin.org malicious Sinkholed
DNS4EU transfer-tws.ink malicious Sinkholed

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
13/13

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026

٨ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. حالة النطاق

    يمكن الوصول إليه ← يتعذر الوصول إليه

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN Microsoft-IIS/10.0 · AS16276 OVH SAS
سمعة عنوان IP IP abuse confidence 0/100 0 reports checked 23/07/2026
مسجّل النطاق غير معروف
جهة الإبلاغ عن إساءة الاستخدامabuse@ovh.ca
عنوان IP 54.39.106.37 CA
الموقع الجغرافيCA Beauharnois, CA
الشبكةAS16276 · OVH Hosting, Inc.
حالة HTTP502 Error
الوقت حتى أول تعذّر للوصول 14 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف23/07/2026
DOM Analysisanalyzed 23/07/2026DOM analysis score 85/100
Submitted URLhttp://transfer-tws.ink/
خوادم الأسماءpdns1.registrar-servers.compdns2.registrar-servers.com
بصمة TLS
رصد TLSصالح منذ 14/07/2026فُحص في 23/07/2026
Favicon Hash
عنوان الصفحة
Crypto Cards
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 81 days

التقنيات

حُدّدت ٣ تقنيات عالية الثقة

Windows Server Application Request Routing IIS
Cloudflare Radar
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

5 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
ChainPatrol
alphaMountain.ai
Forcepoint ThreatSeeker
Fortinet
SOCRadar
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of transfer-tws.ink · checked Jul 23, 2026

68
Needs Work
Performance
FCP
2.92s
First Contentful Paint
LCP
2.92s
Largest Contentful Paint
CLS
0.577
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
2.92s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/transfer-tws.ink"
  title="PhishDestroy threat report for transfer-tws.ink"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>