dfr659[.]it
“Sorry, the website has been stopped”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
Analysis of the domain dfr659.it indicates a high-risk phishing infrastructure currently active as of July 23, 2026. The domain was registered on November 7, 2025, through Dynadot LLC and resolves to the IP address 172.67.157.152, hosted on Cloudflare's network (AS13335). The site returns an HTTP 200 status with the page title 'Sorry, the website has been stopped,' a pattern often observed in phishing domains attempting to evade detection while maintaining operational backend systems. Infrastructure analysis reveals the use of Cloudflare services, including HSTS and HTTP/3, alongside Vue.js and Cloudflare Browser Insights, suggesting a modern web framework likely employed to facilitate malicious activity.
The domain appears on two security blocklists, including PhishDestroy and ScamSniffer, and is flagged by 16 of 93 security vendors on VirusTotal, reinforcing its classification as malicious. Gridinsoft assigns a trust score of 0/100, further corroborating the high-risk assessment. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the threat, as phishing sites frequently leverage valid certificates to appear legitimate. Nameservers are configured under Cloudflare (aria.ns.cloudflare.com and arturo.ns.cloudflare.com), a common tactic to obscure hosting details and complicate takedown efforts.
While the exact phishing campaign or targeted brand remains unconfirmed due to the generic page title, the domain's infrastructure and detection history align with known phishing operations. Defenders should treat this domain as actively malicious and prioritize blocking it at the network and endpoint levels. Monitoring for related domains registered through Dynadot or resolving to Cloudflare's IP ranges may help identify additional threats. Given the domain's persistence and detection by multiple vendors, further investigation into its backend connections and potential affiliate networks is recommended.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of dfr659.it · checked Mar 1, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب