aktifkaanpaylatters[.]dfg[.]my[.]id
“DANA - Apa pun transaksinya selalu ada DANA”
aktifkaanpaylatters.dfg.my.id — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Dana. Zusammenfassung der Beweislage: VirusTotal 15/95 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); URLScan malicious verdict; PhishDestroy score 100/100. Registrar: Cloudflare.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
aktifkaanpaylatters.dfg.my.id was observed serving a page whose title reads “DANA - Apa pun transaksinya selalu ada DANA”. The title directly references the DANA financial service, suggesting an attempt to lure victims into entering credentials for that brand. No SSL certificate was presented, meaning the HTTP connection is unencrypted and susceptible to interception. Reputation services assign the domain extremely low scores: Scamadviser reports a trust rating of 1 / 100, and Gridinsoft records a score of 0 / 100, indicating consensus that the site is untrustworthy.
VirusTotal scans returned 15 detections out of 95 vendor engines, reinforcing the malicious classification. The domain appears on a public phishing blocklist and is actively blocked by the PhishDestroy sinkhole, demonstrating that several security vendors have already taken mitigation steps. Registration data shows the domain was provisioned through Cloudflare, Inc., and DNS resolution points to IP address 104.21.69.153, which belongs to Cloudflare’s AS13335 network and is geolocated in the United States. The site is currently offline, but the underlying Cloudflare front‑end and shared IP address can be reused for future campaigns, so the infrastructure remains of interest to threat actors.
Defenders should continue to block the domain at perimeter firewalls, web proxies, and DNS filtering solutions, and consider adding the IP address 104.21.69.153 to deny lists while monitoring for any re‑registration or new domains that reuse the “aktifkaanpaylatters” prefix. Because the page title explicitly mentions DANA, organizations that rely on DANA for payments should increase user awareness about unsolicited messages that claim to originate from DANA and instruct users to verify URLs before providing credentials.
Sicherheitssignale
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt