الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 21. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

kupnfstvlrmdn[.]update-date[.]web[.]id

“𝗗𝗔𝗡𝗔 𝗜𝗗 | 𝗔𝗸𝘁𝗶𝗳𝗸𝗮𝗻 𝗙𝗶𝘁𝘂𝗿”

حكم التهديد حرجة 95/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 21/94 انتحال العلامة التجارية: Dana
07/03/2026 Dana CDN
ملخص التقرير

kupnfstvlrmdn.update-date.web.id — المحتوى غير متوفر. انتحال العلامة التجارية: Dana; نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 21/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: PT Registrasi Neva Ang….

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
1ABCA936
الدرجة
95/100

This domain is flagged for hosting a credential phishing campaign targeting users of the DANA ID digital payment platform. Analysis of the page title, "DANA ID | Aktifkan Fiturnya," indicates an attempt to impersonate the legitimate DANA service, tricking users into entering sensitive login credentials. The threat type is specifically credential harvesting, with an elevated risk level due to the domain's active targeting of financial service users and its presence on security blocklists. Infrastructure analysis reveals multiple technical indicators of compromise. The domain kupnfstvlrmdn.update-date.web.id was registered on March 07, 2026, through PT Registrasi Neva Angkasa, a registrar commonly associated with malicious domains. It resolves to the IP address 104.21.26.191, hosted on AS13335 (Cloudflare, Inc.), a network frequently leveraged to obscure malicious infrastructure. The domain lacks an SSL certificate, increasing the likelihood of interception of submitted credentials. Detection metrics further corroborate the malicious nature of this domain: 21 out of 95 security vendors on VirusTotal flag it as malicious, and it appears on at least one security blocklist. The domain has since been taken offline, though prior activity suggests a coordinated effort to harvest credentials. Mitigation steps for organizations and end-users include immediate blocking of the domain and its associated IP address (104.21.26.191) at the network perimeter. Users who may have interacted with this domain should be advised to reset their DANA ID credentials and enable multi-factor authentication (MFA) on their accounts. Security teams should monitor for signs of credential reuse across other platforms, as harvested credentials are often tested against multiple services. Additionally, domain registrars and hosting providers should be notified of abusive infrastructure to facilitate takedown efforts. Proactive measures, such as deploying email filtering rules to block messages containing the domain or similar patterns, can reduce the risk of further exposure.

VirusTotal
VirusTotal
21 det.
DNS Security
4/14
رادار CF
ضار
العمر
5 mo
الحالة المرصودة
المحتوى غير متوفر
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 21 / 94 URLQuery لم يتم التحقق منها PhishStats checked — no match recorded OTX no community references رادار CF provider verdict: malicious URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS 4/14 TLS لا توجد بيانات للشهادة WHOIS 5 mo old لقطة شاشة 3 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
DNS Provider Blocks 4 / 14
Controld Adblock Controld Family Controld Malware Quad9 Secure
CF Cloudflare Radar Verdict ضار
Phishing
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer:

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
18/19

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: Dana report ↗
الخادم / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
Registrar (base domain) PT Registrasi Neva Ang… ID(ID)
عنوان IP 104.21.26.191 CDN
الموقع الجغرافيUS San Francisco, US
الشبكةAS13335 · Cloudflare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
Registration (base domain)update-date.web.id · تم إنشاؤه 07/03/2026 (162d)
الوقت حتى أول تعذّر للوصول 8 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف07/03/2026
DOM Analysisanalyzed 29/07/2026score 73/100
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://kupnfstvlrmdn.update-date.web.id/
خوادم الأسماءnia.ns.cloudflare.com
TLS Observationvalid from 11/02/2026scanned 15/03/2026
عنوان الصفحة
𝗗𝗔𝗡𝗔 𝗜𝗗 | 𝗔𝗸𝘁𝗶𝗳𝗸𝗮𝗻 𝗙𝗶𝘁𝘂𝗿
التقنيات · 9 identified
Unpkg

Fast CDN for everything on npm — serves raw files from npm packages.

OWL Carousel
JavaScript libraries

Touch-enabled jQuery plugin for responsive carousel sliders.

J
jQuery CDN

Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.

jQuery
JavaScript libraries

Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.

Google Hosted Libraries
cdnjs
Cloudflare Browser Insights
Analytics RUM

Performance monitoring tool that measures website speed from real users.

www.cloudflare.com
Cloudflare
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

21 / قام موردو الأمان 94 بوضع علامة على هذا المجال
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
BitDefender
Cluster25
CRDF
CyRadar
DNS8
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
كاسبرسكي
Lionic
نتكرافت
OpenPhish
SOCRadar
سوفوس
Trustwave
VIPRE
Webroot

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of kupnfstvlrmdn.update-date.web.id · checked Mar 9, 2026

54
Needs Work
Performance
FCP
2.57s
First Contentful Paint
LCP
7.97s
Largest Contentful Paint
CLS
0.236
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
6.51s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/kupnfstvlrmdn.update-date.web.id"
  title="PhishDestroy threat report for kupnfstvlrmdn.update-date.web.id"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>