khailjstore[.]com
“الخليج ستور - الصفحة الرئيسية”
khailjstore.com — Контент недоступен (HTTP 502). Олицетворение бренда: ["whatsapp"]; Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 0/94; PhishDestroy score 48/100. Регистратор: Namecheap.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis indicates that the domain www.khailjstore.com was registered on 18 April 2026 through Namecheap Inc. The domain resolves to the IPv4 address 178.239.115.115, which Geo‑IP maps to the United Arab Emirates. The authoritative name servers are dns1.registrar-servers.com and dns2.registrar-servers.com, and the site was served over HTTPS using a Let’s Encrypt certificate (R12). The web server identified by banner analysis is Apache HTTP Server, with front‑end libraries including Bootstrap, jQuery, jQuery UI, Moment.js, Polyfill, Sift, and crypto‑js. The page title observed in the HTTP response is “الخليج ستور – …”, encoded in HTML entities.
The domain is currently listed as offline, and it has been added to a single security blocklist and actively blocked by the PhishDestroy feed. Gridinsoft assigns a trust score of 0 / 100, indicating an extremely low confidence rating. VirusTotal scanned the site with 94 antivirus engines and reported no detections; however, the lack of detections does not constitute proof of legitimacy.
The limited evidence suggests the domain is being used for a generic phishing operation, though the exact victim targeting and payload details remain unknown. Defenders should continue to block the domain at network perimeters, monitor DNS queries for the associated IP and name‑server pairs, and add the domain to local threat intelligence lists. Ongoing surveillance of the IP reputation and any future re‑activation of the site is recommended, alongside periodic re‑scans with multiple sandbox services to capture potential malicious behavior if the site returns online.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 8 identified
Popular CSS framework for responsive, mobile-first web development.
Most widely used open-source HTTP server software.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание