kurir[.]pengiriman[.]eventpromo[.]my[.]id
“Account Suspended”
kurir.pengiriman.eventpromo.my.id — المحتوى غير متوفر. نوع الاحتيال: Account Takeover. ملخص الأدلة: VirusTotal 17/93 (Criminal IP, BitDefender, CRDF, CyRadar, ESET); PhishDestroy score 95/100. مسجّل النطاق: PT Cloud Hosting Indon….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain kurir.pengiriman.eventpromo.my.id has been identified as a generic phishing site designed to impersonate legitimate courier or logistics services. Analysis indicates this infrastructure was actively used to deceive users into submitting sensitive information, likely through fake login portals or fraudulent delivery notifications. The domain is currently marked as taken down, though prior activity suggests it was operational for malicious purposes. Infrastructure analysis reveals the domain was registered on January 13, 2025, through PT Cloud Hosting Indonesia. It resolves to the IP address 62.84.180.140, hosted on AS51167 (Contabo GmbH) in France. Security vendors on VirusTotal flagged this domain as malicious, with 17 out of 95 engines detecting it as a threat. The domain appears on one security blocklist, and its page title, 'Account Suspended,' suggests an attempt to mimic a legitimate service disruption notice. Notably, the domain lacks an SSL certificate, a common red flag for fraudulent sites. The risk level for this domain is classified as elevated due to its active use in phishing campaigns and the absence of basic security measures. While the domain is currently inactive, organizations and users should remain vigilant for similar impersonation attempts. Recommended actions include blocking the domain and IP address in network security controls, monitoring for related subdomains or newly registered lookalike domains, and educating users on recognizing phishing indicators such as missing SSL certificates and suspicious registrar details. Historical DNS records and WHOIS data should be preserved for further investigation if required.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب