telezsag.com
“Messenger”
telezsag.com — المحتوى غير متوفر. انتحال العلامة التجارية: Unknown; نوع الاحتيال: Impersonation. ملخص الأدلة: VirusTotal 18/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25, CyRadar); URLQuery 2 det.; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 100/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
ملخص الأدلة
www.telezsag.com is identified as a generic phishing site targeting users by impersonating a legitimate messenger platform. The domain leverages a misleading page title ('Messenger') and an SSL certificate referencing a popular messaging brand, increasing the risk of social engineering attacks. There is no evidence of specific drainer kits, but the configuration suggests intent to harvest sensitive user information, such as credentials or authentication tokens.
Technical analysis reveals multiple threat indicators. VirusTotal reports that 11 out of 95 security vendors classify www.telezsag.com as malicious, supporting the high-risk assessment. The domain is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to IP address 27.124.47.186. Whois records confirm the domain was created on May 26, 2026, indicating a recent setup likely designed to evade existing blocklists. The site is still active at the time of reporting. The use of an SSL certificate referencing a well-known messaging service further supports the phishing intent, as it can deceive users into trusting the fake interface.
Given its active status and the number of security vendors flagging it, www.telezsag.com poses a significant risk for credential theft and user compromise. Security teams should add this domain and its associated IP address to network blocklists and monitor for related indicators of compromise. Users should be warned against interacting with the site, and incident response procedures should be initiated if any credentials are suspected to have been submitted. Continued monitoring is recommended, as the domain remains live and may evolve its tactics.
استخبارات أمن الشبكات Registrar context
Forensic History & Detection Timeline
-
Domain Status Transition Aug 5, 2026 · 18:30 UTCDomain state transitioned from alive to dead.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- درجة الإخفاء
- 0/6
- Last cloaking scan
Scanner note: dns_error: raw=dns_error; via=local_dns_prefilter
Latest Classified Outcome 2026-09-20 04:22:22 UTC
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب