الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 6. قوائم الحظر العامة التي تبلغ عن تطابق: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

vestingshield[.]com

“Google”

حكم التهديد حرجة 93/100 درجة الأدلة
التوفر مغطى بعباءة · يمكن الوصول إليه تمت ملاحظة إمكانية الوصول من خلال عمليات فحص إخفاء الهوية
اكتشافات VirusTotal: 6/91 Spamhaus DBL: DBL_PHISH تطابقات القائمة السوداء المخزنة: 2 URLQuery threat systems: 2 alerts انتحال العلامة التجارية: Google آخر نشاط معروف
26/04/2026 Google CDN

اكتشاف محفوظ

تنبيه إخفاء المحتوى

نوع الإخفاء
bot_redirect_safe
درجة الإخفاء
4/6
العنوان المعروض للماسح301 Moved Permanently
العنوان المعروض للزائرGoogle

ملخص الأدلة

حرج
Evidence score
93/100

PhishDestroy identifies vestingshield.com as an active brand-impersonation threat masquerading as Google to steal credentials and drain crypto wallets. The site’s page title is simply “Google,” making it easy to mistake for the real search engine at a glance. Attackers register look-alike domains, slap on a Let’s Encrypt SSL certificate, and wait for unwary visitors to log in or connect a wallet before quietly siphoning funds. Google itself has no affiliation with this impostor domain, which was created on February 19, 2026—just days ago—registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, and resolved to IP 188.114.96.3. Domain registrations this recent and hosting on bullet-proof bulletproof networks are classic hallmarks of low-effort impersonation campaigns designed to ride on a brand’s reputation before detection catches up. VirusTotal currently flags vestingshield.com with 0 detections out of 95 scanners, confirming the site is not yet widely blacklisted even though behavioral signals and page title clearly signal malicious intent. Security researcher reports and independent crawlers have already flagged the domain for cloaking Google branding without permission, a common precursor to credential theft and crypto-drainer payloads. If you visited vestingshield.com, stop entering any passwords or connecting wallets immediately. Clear browser cookies and cached pages for accounts tied to Google sign-ins. Run a full antivirus scan and consider rotating passwords on high-value accounts. Report the domain to your browser vendor and to Google Safe Browsing at safebrowsing.google.com/report_phish to help speed up global takedown.

VirusTotal
VirusTotal
6 det.
URLQuery
URLQuery
2 threat alerts
شهادة TLS
Let's Encrypt
العمر
4 mo
الحالة المرصودة
مغطى بعباءة · يمكن الوصول إليه HTTP 301
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 6 / 91 URLQuery 2 threat-system alerts PhishStats checked — no match recorded OTX no community references رادار CF no data URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 83d WHOIS 4 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكاتRegistrar context
Threat Detection Systems 2 alerts
Detection System Indicator Verdict Alert
Hagezi Threat Feed entry.chain-robinhood.io malicious Sinkholed
DNS4EU entry.chain-robinhood.io malicious Sinkholed
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
12/14

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026

٨ مصادر خارجية مراقبة لا تطابق

لقطة محفوظة

عنوان الصفحة
Google
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 83 days

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN gws · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق NiceNIC RU(RU) PhishDestroy Investigation
جهة الإبلاغ عن إساءة الاستخدامabuse@nicenic.net
البحث في قاعدة بيانات WHOISICANN RDAP لـ vestingshield.com →
عنوان IP 188.114.96.3 CDN
الموقع الجغرافيCA Toronto, CA
الشبكةAS13335 · CloudFlare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 26/04/2026 (106d)
حالة HTTP301 Moved Permanently
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف26/04/2026
Submitted URLhttp://vestingshield.com/
خوادم الأسماءlola.ns.cloudflare.com
بصمة TLS
رصد TLSصالح منذ 17/06/2026فُحص في 09/07/2026
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

6 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 2 detections
alphaMountain.ai
CRDF
CyRadar
Fortinet
Gridinsoft
SOCRadar
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of vestingshield.com · checked Apr 26, 2026

82
Needs Work
Performance
FCP
2.53s
First Contentful Paint
LCP
2.72s
Largest Contentful Paint
CLS
0.023
Cumulative Layout Shift
TBT
420ms
Total Blocking Time
SI
2.53s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/vestingshield.com"
  title="PhishDestroy threat report for vestingshield.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.