worldlibertyrewards[.]xyz
worldlibertyrewards.xyz — يمكن الوصول إليها · الوصول مقيد (HTTP 403). نوع الاحتيال: Fake Airdrop. ملخص الأدلة: VirusTotal 11/91 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 83/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain worldlibertyrewards.xyz was registered on February 21, 2026 through NiceNIC International Group Co., Limited and is currently listed as taken offline. Technical analysis shows the domain resolves to IP address 172.67.218.136, which belongs to AS13335 Cloudflare, Inc. and is located in the United States. The authoritative nameservers are vick.ns.cloudflare.com and vita.ns.cloudflare.com, indicating the use of Cloudflare’s DNS and CDN services. The site presents an SSL certificate issued by Google Trust Services under the WE1 label, providing a valid TLS handshake despite the malicious purpose.
An HTTP request to the host returns status code 403, and the page title reported by crawlers is "Just a moment...," suggesting a potential challenge or temporary block page rather than the advertised content. The campaign is classified as a "Fake Airdrop" scam, and the domain is blocked by the PhishDestroy feed. It appears on one security blocklist and has been flagged by seven of ninety‑five VirusTotal scanners, demonstrating modest detection coverage.
No additional intelligence such as target brand, payload details, or victim interaction has been published, leaving the exact phishing content unverified beyond the generic airdrop claim. Defenders should continue to block the domain and its associated IP at perimeter firewalls, update DNS filtering policies to include the domain and its Cloudflare‑based nameservers, and monitor for re‑registration or the emergence of similar aliases. Given the limited detection count, threat‑intelligence platforms should be queried regularly for new observations, and any email or web traffic exhibiting the "Just a moment..." title from this host should be treated as suspicious and logged for further investigation.
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-20 02:48:46 UTC
التقنيات · 1 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب