# PhishDestroy threat dossier — webmail.kubukami.com ================================================================ Fetched: 2026-07-26 03:54:00 UTC Canonical: https://phishdestroy.io/domain/webmail.kubukami.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 56/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, BitDefender, CyRadar, ESET, Fortinet, G-Data, SOCRadar, Sophos, VIPRE, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 103.247.9.165 (ID, Cirebon) ASN: AS58487 CV. Rumahweb Indonesia Hosting org: Rumahweb Registrar: CV. Rumahweb Indonesia Nameservers: ["ns1.rumahweb.com", "ns2.rumahweb.com", "ns3.rumahweb.net", "ns4.rumahweb.net"] Page title: Webmail Login HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-08-23 Status: INVALID chain Fingerprint: a992674b4f566a386cb9ce996f08413ffd92e3f13b1cca01dcd02a69c26c2aaa Subject Alternative Names (related infrastructure — often same operator): - autodiscover.kubukami.com - cpanel.kubukami.com - cpcalendars.kubukami.com - cpcontacts.kubukami.com - kubukami.com - mail.kubukami.com - webdisk.kubukami.com - www.kubukami.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-25 12:23:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-26 04:20:22 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-25 12:25:19 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] webmail.kubukami.com Safety Check — Phishing Detected Analysis as of July 25, 2026 indicates that the domain webmail.kubukami.com is currently active and serves a generic phishing campaign. The domain resolves to the name‑server set ns1.rumahweb.com, ns2.rumahweb.com, ns3.rumahweb.net and ns4.rumahweb.net, all of which are operated by the Indonesian hosting provider Rumahweb. Registration was performed through CV. Rumahweb Indonesia, confirming the same hosting relationship. An HTTP request to the root URL returns a 200 OK status, demonstrating that the web server is reachable and delivering content. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy feed, which is a strong indicator of malicious intent. VirusTotal analysis shows that ten of ninety‑one scanned security vendors have flagged the domain, reinforcing the blocklist evidence. No additional intelligence such as SSL certificate details, page title, or related OTX indicators is available at this time. The lack of further public metadata limits the ability to attribute the campaign to a specific actor or to map its full infrastructure, but the combination of blocklist inclusion, multi‑vendor detection, and active HTTP response places the domain in a high‑risk category. Defenders should add webmail.kubukami.com to outbound and inbound filtering rules, enforce DNS‑based blocklist enforcement, and monitor for any related host or IP addresses that appear in network traffic. Because the domain is hosted on a shared infrastructure, threat hunting should also consider other subdomains that resolve to the same name‑servers. Continuous re‑scanning with multi‑vendor services is recommended to capture any future changes in detection status. Until further forensic evidence is gathered, the safest posture is to treat any communications originating from or directed to this domain as malicious and to educate users to avoid interacting with unsolicited messages that reference it. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 827fd6c561d4b1f932f75e0f9a17f766 TLS cert SHA-256: a992674b4f566a386cb9ce996f08413ffd92e3f13b1cca01dcd02a69c26c2aaa ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/webmail.kubukami.com/ JSON API: https://api.destroy.tools/v1/check?domain=webmail.kubukami.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,104 domains (64,738 alive under monitoring, 128,816 confirmed takedowns/dead). Site: https://phishdestroy.io