Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse.support@h4g.co.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
xalqen[.]casa
“Iniciar sesión en tu cuenta Microsoft”
xalqen.casa — لم يتم التحقق منها. انتحال العلامة التجارية: Microsoft; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 6 alerts; URLScan malicious verdict; Spamhaus DBL_SPAM; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: Sav.com.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of xalqen.casa indicates a high risk of brand impersonation, specifically targeting Microsoft. The domain is designed to deceive users into believing they are interacting with a legitimate Microsoft service, potentially leading to the theft of personal information and credentials.
This domain was created on February 18, 2026, and is registered through Sav.com LLC. Infrastructure analysis reveals that xalqen.casa resolves to the IP address 185.221.216.121. The domain has been flagged by 21 out of 95 security vendors on VirusTotal, suggesting a significant level of suspicion within the cybersecurity community. Additionally, the domain appears in one threat intelligence pulse on AlienVault OTX and is listed on one security blocklist. The SSL certificate for the domain is issued by Let's Encrypt, which, while a reputable authority, does not guarantee the legitimacy of the site. The combination of these indicators points to a deliberate attempt to impersonate Microsoft and engage in malicious activities.
To mitigate the risks associated with brand impersonation, users are advised to verify the URL of any Microsoft-related service they visit. Legitimate Microsoft URLs will typically end in .com or .net, and any deviation should be treated with caution. Users should also avoid entering sensitive information on any page that seems suspicious or unfamiliar. It is recommended to report any suspicious activity to Microsoft's security team and to use multi-factor authentication (MFA) wherever possible to protect against unauthorized access. Regularly updating security software and maintaining awareness of common phishing tactics can further enhance security measures.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | xalqen.casa |
malicious | Sinkholed |
| OpenDNS | xalqen.casa |
phishing | Phishing Block |
| DigiCert UltraDNS | xalqen.casa |
malicious | Sinkholed |
| DNS4EU | xalqen.casa |
malicious | Sinkholed |
| OpenDNS | cdn.glitch.global |
phishing | Phishing Block |
| DNS4EU | cdn.glitch.global |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 3 identified
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com ثقة 100٪Google Hosted Libraries is a stable, reliable, high-speed, globally available content distribution network for the most popular, open-source JavaScript libraries.
developers.google.com ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of xalqen.casa · checked Apr 15, 2026
الأدلة والتقارير الخارجية
PD-20260414-CD10BD Recipient: abuse.support@h4g.co هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب