The domain aktiffkan-paylater.tpp.my.id is currently active and has been identified as a generic phishing infrastructure. Analysis shows the domain resolves to the IP address 104.21.8.254, indicating that the hosting service is reachable from the public internet. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy feed, confirming that at least one reputable antiโphishing provider has taken mitigation action. VirusTotal reports that 13 of 91 security vendors have flagged the domain, providing independent corroboration of malicious intent.
Nameserver information could not be retrieved (NS_NOT_FOUND), which limits deeper DNSโbased attribution but does not affect the observed malicious behavior. The threat is classified as highโrisk, and the status remains active as of the report date (July 31, 2026). Defenders should immediately add aktiffkan-paylater.tpp.my.id to network deny lists and enforce DNSโbased blocking for the associated IP 104.21.8.254.
Continuous monitoring of the IP reputation is advised, as the hosting provider may serve additional malicious payloads. Security teams should also consider sharing the detection details with threatโintel sharing platforms to improve collective visibility. Given the limited public intelligence beyond the blocklist presence and vendor detections, further investigation of the hosting environment and potential commandโandโcontrol patterns is recommended to fully map the campaignโs scope.