xn--v-7sbav[.]xn--mhbrgh-3nfac8kferak04aw4hha3153kdaj[.]jonpaki[.]eu[.]com
xn--v-7sbav.xn--mhbrgh-3nfac8kferak04aw4hha3153kdaj.jonpaki.eu.com — لم يتم التحقق منها. ملخص الأدلة: VirusTotal 1/91 (Gridinsoft); PhishDestroy score 71/100. مسجّل النطاق: Instra.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain xn--v-7sbav.xn--mhbrgh-3nfac8kferak04aw4hha3153kdaj.jonpaki.eu.com was registered on February 21, 2026 through Instra Corporation Pty Ltd. It resolves to the IP address 186.2.161.59, which is allocated to AS59692 IQWeb FZ-LLC in Belize. The hosting infrastructure is served by the authoritative name servers ns1.centralnic.net, ns2.centralnic.net, ns3.centralnic.net and a fourth centralnic server that is partially listed. An HTTP request to the domain returns status code 200, indicating that a web service is currently active. The site presents an SSL certificate rated R10, showing that encryption is in place but without additional trust indicators.
VirusTotal reports that the domain has been scanned by 93 vendors, none of which have raised a detection flag; this lack of flags does not constitute a safety guarantee. The domain appears on a single external security blocklist and is actively blocked by the PhishDestroy service, confirming that at least one security provider has classified it as malicious. No additional intelligence such as page title, brand targeting, or malware kit information is available at this time.
Given the generic phishing classification, the combination of an active web service, a valid SSL certificate, and inclusion on a blocklist suggests that the domain is being used to host credential‑harvesting or credential‑relay content. Defenders should continue to block the domain at perimeter firewalls, DNS filters, and endpoint protection solutions. Ongoing monitoring of the IP address, name server changes, and any future VirusTotal or sandbox analyses is recommended to detect potential escalation or payload deployment.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب