tzrsedf76sd8f[.]chalisec25[.]workers[.]dev
“Google”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
Analysis of tzrsedf76sd8f.chalisec25.workers.dev indicates the site was configured to impersonate Gmail, as reflected by the brand target entry and the page title "Google". The domain was registered through Cloudflare, Inc. and utilizes Cloudflare’s DNS infrastructure, with authoritative nameservers ns.cloudflare.com and ns2.cloudflare.com. TLS termination is performed with a certificate issued by Google Trust Services under the WE1 profile, suggesting deliberate use of legitimate‑looking SSL credentials to increase credibility. DNS resolution points to IP address 142.250.185.100, which belongs to AS15169 Google LLC, confirming the host resides within Google’s network in the United States.
HTTP responses return a 403 status code, and the site presently shows as offline, but the presence of HSTS and HTTP/3 indicates that the attacker deployed modern web security features to mimic a legitimate Google service. The infrastructure has been observed on a single security blocklist and is actively blocked by PhishDestroy. VirusTotal scans show that nine of ninety‑five AV engines flagged the domain, reinforcing the malicious classification.
Gridinsoft assigns a trust score of 0 out of 100, further evidencing its low legitimacy. While the site is currently inactive, defenders should continue to block the domain and its resolving IP at the perimeter, incorporate the domain into internal threat‑intel feeds, and monitor for any re‑activation or similar patterns emerging from Cloudflare‑hosted subdomains that use Google‑issued certificates. Ongoing vigilance is advised, especially for users receiving unsolicited Gmail‑related communications that could direct them to this or analogous infrastructure.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of tzrsedf76sd8f.chalisec25.workers.dev · checked Apr 19, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب