Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 22. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

frr[.]ambil-disini[.]web[.]id

“Expired Domain - IDCloudHost”

Threat verdict Critical 95/100 evidence score
Availability Unverified Current reachability is unverified
VirusTotal detections: 22/91 Spamhaus DBL: DBL_BOTNET
Jul 18, 2026
Evidence Summary
CRITICAL
Ref
2345ED8E
Score
95/100

Analysis as of July 19, 2026 indicates that the domain frr.ambil-disini.web.id is actively serving HTTP responses with status code 200 and presents the page title “Expired Domain - IDCloudHost”. The host resolves to IP address 103.193.179.121, which is registered to PT Nara Cakra Studio in Indonesia. The infrastructure remains online, and the domain is currently flagged as high‑risk generic phishing in threat intel feeds. Defensive controls have already added the domain to the PhishDestroy blocklist, and it appears on one additional security blocklist. VirusTotal scans show that 22 of 95 security vendors classify the domain as malicious, reinforcing the high‑risk assessment. While the content of the site has not been publicly dissected, the combination of an expired‑domain landing page, active hosting, and multiple vendor detections suggests a purposeful use for credential‑harvesting or redirect campaigns. Uncertainty remains regarding the exact phishing payload, target audience, or any associated command‑and‑control infrastructure. Defenders should immediately block DNS resolution and HTTP traffic to 103.193.179.121 and frr.ambil-disini.web.id at perimeter devices, add the domain to internal blocklists, and monitor for any related patterns in user traffic. Continuous re‑scanning on VirusTotal and periodic verification of the blocklist status are advised to capture any changes in the domain’s activity.

VirusTotal
VirusTotal
22 det.
Observed status
Unverified
PhishDestroy
DestroyList
Listed
Data coverage VirusTotal 22 / 91 URLQuery not checked PhishStats not checked OTX no community references CF Radar scan completed URLScan capture not submitted URLScan verdict verdict unavailable DNS blocks not checked TLS no certificate data WHOIS not parsed Screenshot not captured Redirect chain not probed
Network Security Intelligence
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer:

Threat Response Pipeline

Discovery
Checks
Reports
Availability
6/8

Public Blocklist Status

Domain Intelligence

Domain
Server / ASN Apache/2.4.52 (Ubuntu) · AS136052 PT Cloud Hosting Indonesia
IP Reputation abuse score 0/100 0 reports checked Jul 19, 2026
IP Address 103.193.179.121 ID
GeoID Cicurug, ID
NetworkAS136052 · PT Nara Cakra Studio
Technical detailsDNS, SSL SANs, timestamps
First DetectedJul 18, 2026
TLS Observationscanned Aug 15, 2026
Favicon Hash
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

22 / 91 security vendors flagged this domain
View on VT
Last analyzed First positive detection Previous stored snapshot: 22 detections
ADMINUSLabs
AlphaSOC
ArcSight Threat Intelligence
BitDefender
Certego
Chong Lua Dao
CRDF
CyRadar
Dr.Web
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Kaspersky
Lionic
Lumu
MalwareURL
SOCRadar
Sophos
Viettel Threat Intelligence
VIPRE
Webroot

Evidence & External Reports

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/frr.ambil-disini.web.id"
  title="PhishDestroy threat report for frr.ambil-disini.web.id"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>