codashophf[.]wewekab[.]web[.]id
“Top Up Free Fire | Promo Terbaru | Codashop Indonesia”
codashophf.wewekab.web.id — असत्यापित. ब्रांड प्रतिरूपण: Cash app; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 15/95 (Criminal IP, BitDefender, CRDF, CyRadar, Ermes); PhishDestroy score 95/100.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
On July 23, 2026 the domain codashophf.wewekab.web.id was observed hosting a high‑risk brand‑impersonation campaign targeting Cash App users. The site was registered on February 21, 2026 and is currently active. DNS resolution points to IP address 172.67.192.13, which belongs to Cloudflare, Inc. (ASN 13335) and is geolocated in the United States. The domain appears on one public security blocklist and has been reported to PhishDestroy, confirming its malicious intent.
VirusTotal scans show that 15 of 95 AV engines flag the domain as malicious, indicating a moderate consensus among scanners. The web server presents an SSL certificate identified as “WE1”, and an HTTP 302 redirect is returned for the initial request. The only page title retrieved is “Top Up Free Fire | Promo Terbaru | Codashop Indonesia”, which is unrelated to Cash App and suggests the operator is leveraging unrelated promotional content to attract victims. No additional intelligence such as login page screenshots, JavaScript payloads, or credential‑stealing behavior has been released, so the exact phishing flow remains unknown.
Defenders should block the domain at DNS and proxy layers, add the IP address 172.67.192.13 to blocklists, and monitor for similar Cloudflare‑hosted URLs that reference the same page title or SSL certificate. Continuous re‑scanning on VirusTotal and inclusion in threat‑intel feeds will help track any changes in detection scores. Organizations that rely on Cash App for employee reimbursements should educate users about unsolicited “top‑up” offers and enforce multi‑factor authentication to mitigate credential compromise.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।