aktifkaanpaylatters[.]dfg[.]my[.]id
“DANA - Apa pun transaksinya selalu ada DANA”
aktifkaanpaylatters.dfg.my.id — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Dana. साक्ष्य सारांश: VirusTotal 15/95 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); URLScan malicious verdict; PhishDestroy score 100/100. रजिस्ट्रार: Cloudflare.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
aktifkaanpaylatters.dfg.my.id was observed serving a page whose title reads “DANA - Apa pun transaksinya selalu ada DANA”. The title directly references the DANA financial service, suggesting an attempt to lure victims into entering credentials for that brand. No SSL certificate was presented, meaning the HTTP connection is unencrypted and susceptible to interception. Reputation services assign the domain extremely low scores: Scamadviser reports a trust rating of 1 / 100, and Gridinsoft records a score of 0 / 100, indicating consensus that the site is untrustworthy.
VirusTotal scans returned 15 detections out of 95 vendor engines, reinforcing the malicious classification. The domain appears on a public phishing blocklist and is actively blocked by the PhishDestroy sinkhole, demonstrating that several security vendors have already taken mitigation steps. Registration data shows the domain was provisioned through Cloudflare, Inc., and DNS resolution points to IP address 104.21.69.153, which belongs to Cloudflare’s AS13335 network and is geolocated in the United States. The site is currently offline, but the underlying Cloudflare front‑end and shared IP address can be reused for future campaigns, so the infrastructure remains of interest to threat actors.
Defenders should continue to block the domain at perimeter firewalls, web proxies, and DNS filtering solutions, and consider adding the IP address 104.21.69.153 to deny lists while monitoring for any re‑registration or new domains that reuse the “aktifkaanpaylatters” prefix. Because the page title explicitly mentions DANA, organizations that rely on DANA for payments should increase user awareness about unsolicited messages that claim to originate from DANA and instruct users to verify URLs before providing credentials.
सुरक्षा संकेत
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।