xsec[.]keplindomi[.]workers[.]dev
“Pegasus - Next-Generation Data Infrastructure”
ملخص الأدلة
The domain xsec.keplindomi.workers.dev is listed as an active generic phishing site with a specific focus on cryptocurrency drainage. The domain was registered on May 01 2026 through Cloudflare, Inc. and resolves to the IP address 188.114.97.3, which is hosted in Canada by Cloudflare’s network. HTTP requests return a 200 status code, and the site presents a TLS certificate issued by Let’s Encrypt (E8). Technical profiling shows the front‑end is built with Three.js and Tailwind CSS, and assets are served from cdnjs. The server enforces HTTP Strict Transport Security and negotiates HTTP/3 connections, indicating modern configuration. No custom nameserver records were identified, and the Gridinsoft trust score is 0 out of 100, reflecting a high‑risk assessment. The visible page title, “Pegasus – Next‑Generation Data Infrastructure,” is unrelated to the underlying activity and is likely used to lure victims. Intelligence classifies the operation as a “Crypto Drainer” scam, suggesting the site attempts to trick users into transferring cryptocurrency to addresses controlled by the adversary. The domain appears on one security blocklist and is already blocked by PhishDestroy, though VirusTotal currently shows zero detections. Defenders should add 188.114.97.3 and xsec.keplindomi.workers.dev to network deny lists and enable DNS sink‑holing for the domain. Monitoring of outbound traffic for attempted crypto‑wallet connections to unknown addresses is advised. Continuous re‑evaluation is required, as the threat actor may modify the payload or shift hosting while retaining the same domain fingerprint.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026
التقنيات
حُدّدت ٦ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of xsec.keplindomi.workers.dev · checked May 1, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب