xn--ve-6kca[.]xn--mppshbr-2fgcd9li3a70yha6062idaj[.]upkyberwallet[.]com
“upkyberwallet.com | 522: Connection timed out”
xn--ve-6kca.xn--mppshbr-2fgcd9li3a70yha6062idaj.upkyberwallet.com — لم يتم التحقق منها. نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 6/91 (ChainPatrol, alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar); PhishDestroy score 71/100. مسجّل النطاق: MAT BAO.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, observed on July 12, 2026, is classified as an active crypto drainer threat with a high-risk designation. Infrastructure analysis reveals the domain was registered on February 21, 2026, through MAT BAO CORPORATION and currently resolves to IP address 104.21.112.1, hosted on Cloudflare's network (AS13335) in the United States. The domain employs Cloudflare nameservers (kallie.ns.cloudflare.com and kyle.ns.cloudflare.com) and utilizes HTTP/3 protocol, with a Let's Encrypt SSL certificate issued under the E8 chain. The page title, 'upkyberwallet.com | 522: Connection timed out,' suggests either deliberate misconfiguration or a temporary outage, which is consistent with evasion tactics used by crypto drainer operations. A 403 HTTP status indicates restricted access, potentially limiting automated analysis. The domain appears on one security blocklist and is explicitly flagged as a crypto scam by at least one vendor. While two of 95 security vendors on VirusTotal have detected malicious indicators, the absence of broader detection does not reduce the assessed risk, as crypto drainers often employ short-lived infrastructure to evade detection. Defenders should treat this domain as hostile infrastructure. The use of Cloudflare does not imply legitimacy, as threat actors frequently abuse its services for anonymity and DDoS protection. Network-level blocking is recommended, particularly for organizations handling cryptocurrency transactions. Further monitoring is advised, as the domain remains active and may resume operations under a different configuration. The exact content of the site has not been analyzed, but the classification as a crypto drainer indicates it is likely designed to siphon digital assets from victims' wallets.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: upkyberwallet.com
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain upkyberwallet.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب