dfr659[.]it
Análisis de phishing y seguridad de dfr659.it
“Sorry, the website has been stopped”
dfr659.it — Último activo conocido (HTTP 200). Suplantación de marca: Genericcrypto; Tipo de estafa: Impersonation. Resumen de las pruebas: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 100 det.; URLScan malicious verdict; 1 external blocklist match (ScamSniffer); PhishDestroy score 100/100. Registrador: Dynadot.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain dfr659.it indicates a high-risk phishing infrastructure currently active as of July 23, 2026. The domain was registered on November 7, 2025, through Dynadot LLC and resolves to the IP address 172.67.157.152, hosted on Cloudflare's network (AS13335). The site returns an HTTP 200 status with the page title 'Sorry, the website has been stopped,' a pattern often observed in phishing domains attempting to evade detection while maintaining operational backend systems. Infrastructure analysis reveals the use of Cloudflare services, including HSTS and HTTP/3, alongside Vue.js and Cloudflare Browser Insights, suggesting a modern web framework likely employed to facilitate malicious activity.
The domain appears on two security blocklists, including PhishDestroy and ScamSniffer, and is flagged by 16 of 93 security vendors on VirusTotal, reinforcing its classification as malicious. Gridinsoft assigns a trust score of 0/100, further corroborating the high-risk assessment. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the threat, as phishing sites frequently leverage valid certificates to appear legitimate. Nameservers are configured under Cloudflare (aria.ns.cloudflare.com and arturo.ns.cloudflare.com), a common tactic to obscure hosting details and complicate takedown efforts.
While the exact phishing campaign or targeted brand remains unconfirmed due to the generic page title, the domain's infrastructure and detection history align with known phishing operations. Defenders should treat this domain as actively malicious and prioritize blocking it at the network and endpoint levels. Monitoring for related domains registered through Dynadot or resolving to Cloudflare's IP ranges may help identify additional threats. Given the domain's persistence and detection by multiple vendors, further investigation into its backend connections and potential affiliate networks is recommended.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 5 identified
Progressive JavaScript framework for building user interfaces.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of dfr659.it · checked Mar 1, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.