a25365[.]cc
“a25365.cc”
Pengamatan tersimpan
Perbedaan judul yang diamati
Ringkasan bukti
This domain, a25365.cc, is flagged as a high-risk phishing endpoint with active redirection behavior. Analysis indicates the domain was registered on February 21, 2026, through a registrar and currently resolves to IP 27.124.41.84, hosted on AS152194 in Hong Kong. The HTTP response code is 302, suggesting an immediate redirect to another destination, which is consistent with phishing infrastructure designed to evade detection or dynamically serve malicious content based on visitor profiles. Infrastructure review reveals the domain uses nameservers v1s1.xundns.com and v1s2.xundns.com, a pattern observed in other recently reported phishing campaigns. The SSL certificate is issued to 'Default Company Ltd,' a generic placeholder commonly associated with low-effort or automated malicious setups. Security vendors on VirusTotal have flagged this domain 16 times out of 95, indicating moderate consensus on its malicious nature, though the specific impersonated brand or service remains unconfirmed. The domain appears on one security blocklist and was referenced in a single threat intelligence pulse, suggesting limited but targeted distribution. Defenders should treat this domain as an active threat. The 302 redirect behavior may obscure the final payload, so network-level blocking of 27.124.41.84 and the associated nameservers is recommended. Logs should be reviewed for any outbound connections to this IP or domain, particularly from endpoints that handle credentials or financial data. Given the domain's recent registration and lack of legitimate historical activity, it is unlikely to serve any valid business purpose. If internal access is detected, immediate isolation of affected systems and credential rotation should be prioritized.
Data Coverage
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | a25365.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | a25365.cc |
malicious | Sinkholed |
| Cloudflare DNS | hd365756.com |
malicious | Sinkholed |
| DigiCert UltraDNS | hd365756.com |
malicious | Sinkholed |
| DNS4EU | hd365756.com |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 11/08/2026
Linimasa deteksi
-
Cloudflare Radar
Pemindaian Cloudflare Radar tersimpan · Buka pemindaian
-
Cloudflare Radar
Pemindaian Cloudflare Radar tersimpan · Buka pemindaian
Analisis VirusTotal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive