wjla-tiwaitlf-tiwaitlf-wjla[.]jindunqst[.]com
“域名停靠”
wjla-tiwaitlf-tiwaitlf-wjla.jindunqst.com — لم يتم التحقق منها. ملخص الأدلة: VirusTotal 15/91 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain wjla-tiwaitlf-tiwaitlf-wjla.jindunqst.com was created on 24 September 2024 through the registrar Gname.com Pte. Ltd. and is delegated to the Alibaba Cloud DNS servers jm1.alidns.com and jm2.alidns.com. DNS resolution points to the IPv4 address 103.75.15.107, which belongs to AS132839 POWER LINE DATACENTER and is geolocated in Hong Kong. The site does not present an SSL/TLS certificate, meaning it is only reachable over HTTP. The single page that was observed returns the title “域名停靠”, which provides no indication of the intended victim target or malicious functionality. Security monitoring has placed the domain on one blocklist and it is actively blocked by the PhishDestroy service.
Reputation scoring from Gridinsoft rates the domain at 0 out of 100, indicating a complete lack of trust. VirusTotal analysis shows that 15 of 95 scanned security vendors flagged the domain as malicious, reinforcing the suspicion of phishing activity. The domain is currently reported as offline, and no further HTTP response details are available. Based on the available evidence, the infrastructure appears to be a typical short‑lived phishing host that relies on a low‑reputation DNS configuration, a non‑TLS web server, and a Hong Kong‑based hosting provider.
The precise phishing payload, target brand, or credential‑stealing technique has not been observed, leaving the exact attack vector unknown. Defenders should immediately add 103.75.15.107 to network deny lists, enforce blocking of the fully qualified domain name at DNS and proxy layers, and monitor for additional domains that resolve to the same IP or use the same nameservers. Continuous re‑scanning of the domain through multi‑vendor services such as VirusTotal is recommended in case the offline status changes.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: jindunqst.com
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain jindunqst.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب