duplicate-disabled-189753.invalid
“NAGA99 Sewa Bar Mobile Terbaik untuk Pernikahan & Event”
The domain www.barexpert.pl was observed on July 12, 2026 delivering a credential phishing page titled “NAGA99 Sewa Bar Mobile Terbaik untuk Pernikahan & Event”
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
The domain www.barexpert.pl was observed on July 12, 2026 delivering a credential phishing page titled “NAGA99 Sewa Bar Mobile Terbaik untuk Pernikahan & Event”. The site returns HTTP 200, is listed on a single security blocklist and has been flagged by PhishDestroy. VirusTotal scans show three out of ninety‑five security vendors marking the domain as malicious. The page’s SSL certificate is issued by home.pl S.A., using a DV TLS G2 R35 CA, confirming the certificate chain is publicly trusted. Technical infrastructure indicates the domain resolves to IP address 188.128.210.31, which resolves to a hosting provider located in Poland (home.pl S.A.). The domain was registered on April 02, 2026 through home.pl sp. z o.o., and utilizes the DNS resolvers dns.home.pl, dns2.home.pl, and dns3.home.pl. A Gridinsoft trust score of 0 out of 100 further underscores the suspicious nature of the host. The content presented mimics a legitimate service for mobile bar rentals, targeting users seeking wedding or event supplies. By leveraging a familiar brand‑like name (“NAGA99”) the page attempts to harvest login credentials and personal data. While the exact phishing kit or exfiltration endpoint is not disclosed in the collected intelligence, the presence of a valid TLS certificate and a functional web server suggests a low‑cost, rapid‑deployment operation typical of credential‑phishing campaigns. Defenders should block resolution of www.barexpert.pl at network perimeter and add the associated IP 188.128.210.31 to deny lists. Email gateways should be tuned to detect messages containing the “NAGA99 Sewa Bar Mobile” phrase or similar Indonesian‑language promotional text. Continuous monitoring of the home.pl name‑server range is advised, as the same provider has hosted multiple malicious domains in recent months. Incident response teams should also review logs for any outbound connections to the identified IP and investigate potential credential compromises.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | cdn.decibelinsight.net/i/14121/1818647/di.js |
audit | Hunting_JS_WebAssembly |
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/63/14d/common.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | salesuplift.store |
malicious | Sinkholed |
Forensic Intelligence
Threat Response Pipeline
Public Blocklist Status
Detection-evasion analysis
Cloaking suspected: scanner and visitor titles differ
Not observed
No cloaking was observed in the stored scan
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Cloaking score
- 0/6
- Last cloaking scan
- Server header seen by scanner
IdeaWebServer/6.4.1
Scanner note: alive_content: raw=ok; http=200; via=https_proxy; server=IdeaWebServer/6.4.1
Stored Capture · 3 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of duplicate-disabled-189753.invalid · checked Jun 26, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive