wlflibartyfinancial[.]xyz
wlflibartyfinancial.xyz — المحتوى غير متوفر (HTTP 502). ملخص الأدلة: VirusTotal 4/93 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet); Spamhaus DBL_PHISH; PhishDestroy score 66/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of wlflibartyfinancial.xyz indicates that the domain was registered on February 21, 2026 and is currently offline. The site resolves to IP address 104.21.64.1, which belongs to AS13335 operated by Cloudflare, Inc., locating the hosting infrastructure in the United States. A TLS certificate identified as "WE1" was in place at the time of observation, confirming that the domain was serving HTTPS traffic. The HTTP response returned the page title "Just a moment...," a generic placeholder often associated with automated redirection or challenge pages, but no further content details are available.
VirusTotal scanned the domain and recorded four positive detections out of ninety-three submitted security vendors, suggesting that multiple anti‑malware engines flagged the host as malicious. The domain is listed on a single security blocklist and has been actively blocked by the PhishDestroy service, reinforcing the assessment that it was being used for phishing purposes. While the exact phishing campaign details, target brand, and payload are not disclosed, the combination of recent registration, cloud‑based hosting, TLS presence, and multiple vendor detections aligns with typical infrastructure used for short‑lived phishing operations.
Defenders should continue to monitor DNS queries for wlflibartyfinancial.xyz, enforce blocklist updates that include this domain, and ensure that any residual client connections to the associated IP are terminated. Additional investigation of related subdomains or similar Cloudflare‑hosted IP ranges may reveal further malicious assets. Organizations should also verify that endpoint protection solutions are receiving the latest signatures that flag the four detecting vendors, and consider reporting any observed traffic to threat‑intel sharing platforms to improve communal visibility.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب