waitingpackageco[.]web[.]app
فحص التصيد والأمان للنطاق waitingpackageco.web.app
“Verification”
waitingpackageco.web.app — آخر نشاط معروف (HTTP 200). نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 3 alerts; CF Radar malicious; PhishDestroy score 100/100. مسجّل النطاق: Google Domains.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of the domain waitingpackageco.web.app indicates active involvement in a delivery scam operation, as classified by threat intelligence sources. The domain, registered on April 15, 2026, through Google LLC, resolves to the IP address 199.36.158.100, hosted within the United States under Google LLC infrastructure. The site returns an HTTP 200 status code, signaling an operational web presence, and presents a page titled 'Verification,' which aligns with common phishing tactics used to deceive users into submitting personal or financial details under false pretenses. Technical indicators reveal the use of Firebase and reCAPTCHA, alongside HSTS and HTTP/3 protocols, suggesting an attempt to appear legitimate while maintaining modern web security standards. The SSL certificate is issued by Google Trust Services (WR4), which does not inherently validate the site's legitimacy but ensures encrypted connections. The domain lacks configured nameservers, a potential red flag for hastily deployed malicious infrastructure. Trust scores from Gridinsoft and Scamadviser are both at 1/100, reinforcing its classification as high-risk. The domain appears on one security blocklist and is explicitly blocked by PhishDestroy. As of July 12, 2026, 15 out of 94 security vendors on VirusTotal flag the domain as malicious, providing further evidence of its harmful nature. Defenders should treat this domain as a confirmed delivery scam threat, block it at the network level, and monitor for associated indicators of compromise. The exact content or branding targeted by the site remains unconfirmed beyond the 'Verification' page title, and further analysis of the site's payload is recommended to identify additional attack vectors or victim profiles.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | waitingpackageco.web.app |
malicious | Sinkholed |
| OpenDNS | waitingpackageco.web.app |
phishing | Phishing Block |
| DNS4EU | waitingpackageco.web.app |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 4 identified
Google platform for building mobile and web applications with backend services.
Google's bot-challenge service. On phishing sites, used to appear legitimate and filter out automated scanners.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of waitingpackageco.web.app · checked Apr 15, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب