frr[.]ambil-disini[.]web[.]id
“Expired Domain - IDCloudHost”
frr.ambil-disini.web.id — No verificado. Resumen de las pruebas: VirusTotal 22/91 (ADMINUSLabs, AlphaSOC, ArcSight Threat Intelligence, BitDefender, Certego); Spamhaus DBL_BOTNET; PhishDestroy score 95/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis as of July 19, 2026 indicates that the domain frr.ambil-disini.web.id is actively serving HTTP responses with status code 200 and presents the page title “Expired Domain - IDCloudHost”. The host resolves to IP address 103.193.179.121, which is registered to PT Nara Cakra Studio in Indonesia. The infrastructure remains online, and the domain is currently flagged as high‑risk generic phishing in threat intel feeds. Defensive controls have already added the domain to the PhishDestroy blocklist, and it appears on one additional security blocklist. VirusTotal scans show that 22 of 95 security vendors classify the domain as malicious, reinforcing the high‑risk assessment. While the content of the site has not been publicly dissected, the combination of an expired‑domain landing page, active hosting, and multiple vendor detections suggests a purposeful use for credential‑harvesting or redirect campaigns. Uncertainty remains regarding the exact phishing payload, target audience, or any associated command‑and‑control infrastructure. Defenders should immediately block DNS resolution and HTTP traffic to 103.193.179.121 and frr.ambil-disini.web.id at perimeter devices, add the domain to internal blocklists, and monitor for any related patterns in user traffic. Continuous re‑scanning on VirusTotal and periodic verification of the blocklist status are advised to capture any changes in the domain’s activity.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.