uk41webdesk[.]us
فحص التصيد والأمان للنطاق uk41webdesk.us
“Website uk41webdesk.us is ready. The content is to be added”
uk41webdesk.us — خطأ في الخادم (HTTP 525). نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. مسجّل النطاق: DYNADOT.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain uk41webdesk.us was flagged on April 10, 2026 by PhishDestroy and categorized as a generic phishing host designed to mimic official Microsoft licensing portals. No specific drainer kit family is attached to this entry, but the page content and social-engineering prompts closely resemble known Windows product key scams circulating during the same period. Security researchers have observed that the page attempts to coerce victims into downloading “cracks” or entering fake product keys under the pretence of activation failure, a method frequently used to harvest credentials and deliver secondary payloads.
EXACT technical indicators align with the under-investigation classification: VirusTotal shows 1/95 detections on first scan, the domain was created on April 10, 2026, resolves to Cloudflare IP 172.67.183.128 via a Let’s Encrypt SSL certificate, and is registered through Dynadot LLC. As of the seed ddeb35 query, the domain remains absent from Google Safe Browsing and public blocklists, indicating a recently stood-up threat that has not yet propagated to major threat feeds. The asynchronous timestamp suggests an accelerated setup likely intended for a short-lived campaign.
Current status is active and the page remains accessible. Immediate actions for defenders include adding the domain and IP to browser blocklists and SIEM rules, and blocking outbound connections to 172.67.183.128 at the network perimeter. Because the domain uses a legitimate-looking Let’s Encrypt certificate and Cloudflare routing, traditional URL-based detection may miss it; advanced inspection via TLS fingerprinting or JA3/JA3S monitoring is recommended. The remaining risk is elevated due to low VT coverage and unblocked status, but mitigation can be achieved rapidly by blocking the IP and domain, combined with user education on Microsoft licensing portals and the dangers of downloaded cracks.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of uk41webdesk.us · checked Apr 12, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب