الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 2. قوائم الحظر العامة التي تبلغ عن تطابق: 1. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

wlshibonk[.]web[.]app

“PUMP Airdrop”

حكم التهديد حرجة 76/100 درجة الأدلة
التوفر لم يتم التحقق منها لم يتم التحقق من إمكانية الوصول الحالية
اكتشافات VirusTotal: 2/91 تطابقات القائمة السوداء المخزنة: 1 انتحال العلامة التجارية: Phantom
10/10/2025 Phantom

ملخص الأدلة

حرج
Evidence score
76/100

This domain, wlshibonk.web.app, poses a high-risk brand impersonation threat targeting users of the Phantom cryptocurrency wallet. The site falsely advertises a "PUMP Airdrop" to deceive visitors into connecting their wallets or divulging sensitive credentials, such as recovery phrases or private keys. Such scams typically lead to unauthorized access to digital assets, immediate fund theft, or installation of malicious smart contracts designed to drain wallets upon interaction. Analysis indicates the domain is registered through Google LLC and resolves to the IP address 216.198.79.67, hosted on Amazon.com, Inc. infrastructure (AS16509). The SSL certificate is issued by Google Trust Services (WR4), a common tactic to appear legitimate. As of the latest scan, only 1 out of 95 security vendors on VirusTotal flags this domain, suggesting it may evade detection by less sophisticated security tools. The domain appears on two security blocklists and is actively blocked by at least two threat intelligence platforms. No historical registration data is publicly available, but the use of Google's web.app subdomain service suggests recent creation to exploit current trends in cryptocurrency airdrops. Users who visited wlshibonk.web.app should assume their wallet credentials or connected sessions may be compromised. Immediate action is required: revoke any active wallet connections to the site via the Phantom wallet interface, transfer funds to a new wallet with a fresh recovery phrase, and monitor all linked accounts for unauthorized transactions. If recovery phrases or private keys were entered, consider all associated wallets permanently compromised. Enable transaction previews and multi-factor authentication where available, and report the domain to relevant threat intelligence platforms to aid in broader detection efforts. Avoid interacting with any further communications related to this airdrop, as follow-up phishing attempts via email or social media are likely.

VirusTotal
VirusTotal
2 det.
شهادة TLS
منتهية الصلاحية أو غير متحقق منها -130d
العمر
10 mo
الحالة المرصودة
لم يتم التحقق منها
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 2 / 91 URLQuery تم تخزين التقرير - الحكم التفصيلي معلق PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 10 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
11/13

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026

٩ مصادر خارجية مراقبة لا تطابق

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN ESF · AS16509 AMAZON-02, US
سمعة عنوان IP IP abuse confidence 0/100 13 reports checked 18/07/2026
مزود المنصة Google Domains US(US)
جهة الإبلاغ عن إساءة الاستخدامcloud-abuse@google.com, network-abuse@google.com
عنوان IP 216.198.79.67 US
الموقع الجغرافيUS Walnut, US
الشبكةAS16509 · Amazon.com, Inc.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف10/10/2025
DOM Analysisanalyzed 11/03/2026DOM analysis score 76/1001 brand signal
Submitted URLhttps://wlshibonk.web.app/
خوادم الأسماءns-cloud.googledomains.com
بصمة TLS
رصد TLSصالح منذ 05/01/2026فُحص في 11/03/2026
الأسماء البديلة لموضوع TLSweb.app
Favicon Hash
عنوان الصفحة
PUMP Airdrop
Impersonates
Phantom
شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن Google Trust Services / WR4

الاستخبارات الجنائية الرقمية

External Scripts 2
https://cdn.jsdelivr.net/npm/disable-devtool https://turcdn.com/storage/index.js
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

2 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 1 detection
alphaMountain.ai
Gridinsoft
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of wlshibonk.web.app · checked Mar 2, 2026

80
Needs Work
Performance
FCP
2.86s
First Contentful Paint
LCP
3.97s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
4.44s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/wlshibonk.web.app"
  title="PhishDestroy threat report for wlshibonk.web.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>