ultiversedao[.]xyz
“Ultiverse Rewards Claim”
ultiversedao.xyz — المحتوى غير متوفر (HTTP 502). ملخص الأدلة: VirusTotal 16/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100. مسجّل النطاق: PDR.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis indicates that the domain ultiversedao.xyz was registered on 21 February 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. The authoritative name servers max.ns.cloudflare.com and piper.ns.cloudflare.com resolve the zone to the IP address 188.114.97.3, which belongs to Cloudflare’s AS13335 network in the United States. The site was protected by a Google Trust Services certificate (WE1) and was reachable via HTTP/3, confirming its use of Cloudflare’s CDN and edge services. The page title observed during the brief live window was “Ultiverse Rewards Claim”, suggesting an attempt to lure victims with a rewards‑claim narrative. VirusTotal scans recorded 16 detections out of 95 participating vendors, and the domain appears on four independent blocklists – PhishDestroy, MetaMask, ScamSniffer, and SEAL – reinforcing its malicious classification.
Gridinsoft assigned a trust score of 0 out of 100, and AlienVault OTX includes the domain in a single threat‑intel pulse. The overall risk rating is high, and the site has already been taken offline at the time of reporting. Uncertainty remains around the specific phishing kit or payload used, as no additional content analysis or payload hashes have been disclosed. The short lifespan of the site limits the amount of forensic artefacts available, and the use of Cloudflare can obscure the true backend infrastructure. Nonetheless, the convergence of multiple vendor detections, blocklist entries, a zero‑trust score, and the observed “Rewards Claim” page title provides sufficient confidence to treat the domain as a high‑confidence phishing indicator.
Defenders should immediately add ultiversedao.xyz to existing URL filtering, DNS sinkhole, and endpoint block lists. Network monitoring should flag any outbound connections to the IP 188.114.97.3, and TLS inspection rules should be updated to capture the Google Trust Services certificate fingerprint for correlation.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب