الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 3. قوائم الحظر العامة التي تبلغ عن تطابق: 3. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

web3oi[.]online

“1 new message”

حكم التهديد حرجة 84/100 درجة الأدلة
التوفر آخر نشاط معروف أحدث مراقبة إمكانية الوصول المخزنة
اكتشافات VirusTotal: 3/91 تطابقات القائمة السوداء المخزنة: 3 انتحال العلامة التجارية: Across آخر نشاط معروف
29/10/2025 Across

ملخص الأدلة

حرج
Evidence score
84/100

web3oi.online was registered on 23 October 2025 through NameCheap, Inc. and currently resolves to the IPv4 address 66.29.137.142, which is assigned to AS22612 (Namecheap) in the United States. The domain serves content over HTTPS using a Let’s Encrypt certificate (R13) and advertises HSTS. DNS resolution is handled by dns1.namecheaphosting.com and dns2.namecheaphosting.com. HTTP requests receive a 200 OK response, indicating an actively hosted web service. Infrastructure analysis reveals a modern JavaScript stack: Node.js, React, Next.js, Vercel hosting, and Webpack bundling. The Gridinsoft trust score for the site is 0 out of 100, reflecting a highly suspicious rating. VirusTotal scans show that 3 of 95 security vendors have flagged the domain as malicious, reinforcing the suspicion despite a low detection count. The site presents an SSL certificate issued by Let’s Encrypt, which is common for both legitimate and illicit sites. Threat intelligence tags the site as a seed_phish and wallet_connect_phish operation that employs an “Airdrop Scam” phishing kit. The brand target is listed as “across,” indicating a broad impersonation strategy rather than a single brand. The page title returned by the server is “1 new message,” and no further content analysis has been published. The domain is currently listed on four security blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura, confirming active detection by multiple anti‑phishing feeds. While the exact phishing landing page has not been captured, the combination of a fresh domain, low trust score, active blocklist listings, and the presence of a known airdrop‑related kit suggests a high‑risk credential‑ harvesting campaign. Defenders should block the domain and its associated IP at perimeter defenses, monitor DNS queries for the hostnames, and consider sinkholing the address space if feasible. Continuous re‑evaluation is advised, as the operators may shift to new infrastructure or modify the phishing kit.

VirusTotal
VirusTotal
3 det.
شهادة TLS
منتهية الصلاحية أو غير متحقق منها -70d
العمر
10 mo
الحالة المرصودة
آخر نشاط معروف HTTP 200
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 3 / 91 URLQuery تم تخزين التقرير - الحكم التفصيلي معلق PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 10 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
11/13

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026

٧ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. VirusTotal

    3 ← 0

  2. VirusTotal

    3 ← 0

  3. VirusTotal

    3 ← 0

  4. VirusTotal

    3 ← 0

  5. VirusTotal

    3 ← 1

لقطة محفوظة

عنوان الصفحة
1 new message
Impersonates
Across Arbitrum Discord Ethereum Optimism Polygon Solana Zksync
شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن Let's Encrypt / R13

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN LiteSpeed · AS22612 NAMECHEAP-NET, US
سمعة عنوان IP IP abuse confidence 0/100 0 reports checked 18/07/2026
عنوان IP 66.29.137.142 US
الموقع الجغرافيUS Phoenix, US
الشبكةAS22612 · Namecheap, Inc.
التسجيلتم إنشاؤه 23/10/2025 (291d) Expires 23/10/2026
Elapsed Since First Report 137 days
ما الذي نحتسبه Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: آخر نشاط معروف.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
حالة HTTP200
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف29/10/2025
DOM Analysisanalyzed 11/03/2026DOM analysis score 75/1008 brand signals
Submitted URLhttp://web3oi.online/
خوادم الأسماءdns1.namecheaphosting.comdns2.namecheaphosting.com
بصمة TLS
رصد TLSصالح منذ 04/03/2026فُحص في 11/03/2026
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.

التقنيات

حُدّدت ٦ تقنيات عالية الثقة

Node.js React Vercel Next.js HSTS Webpack
Cloudflare Radar
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

3 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 3 detections
alphaMountain.ai
CRDF
Gridinsoft
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of web3oi.online · checked Mar 2, 2026

95
Good
Performance
FCP
0.91s
First Contentful Paint
LCP
1.37s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
203ms
Total Blocking Time
SI
3.55s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/web3oi.online"
  title="PhishDestroy threat report for web3oi.online"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.