Lompat ke laporan keamanan
⚠️
Domain ini telah ditandai sebagai berbahaya
Mesin keamanan melaporkan deteksi: 20. Daftar blokir publik yang melaporkan kecocokan: 2. Berhati-hatilah — jangan memasukkan kredensial atau informasi pribadi.
Keamanan domain dan intelijen ancaman

auspost-app[.]com

Pemeriksaan phishing dan keamanan auspost-app.com

“AusPost App — Download Now”

Putusan ancaman Kritis 100/100 skor bukti
Ketersediaan Terakhir diketahui aktif Pengamatan keterjangkauan tersimpan terbaru
Sinyal risiko
Deteksi Total Virus: 20/91 Spamhaus DBL: DBL_SPAM Daftar blokir yang disimpan cocok: 2 Terakhir diketahui aktif
20/91 VT 15/06/2026 2 Blocklists TM TM
Ringkasan laporan

auspost-app.com — Terakhir diketahui aktif (HTTP 200). Ringkasan bukti: VirusTotal 20/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); Google Safe Browsing flagged; Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Registrar: OwnRegistrar.

Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.

Ringkasan bukti
KRITIS
Ref
54D8ACFD
Skor
100/100

This domain, auspost-app.com, is a confirmed phishing site designed to impersonate the legitimate Australia Post (AusPost) application download portal. The site presents a fraudulent page titled 'AusPost App — Download Now,' targeting users seeking official postal service software. Analysis indicates the domain is engineered to harvest login credentials, distribute malicious payloads, or facilitate financial fraud through social engineering tactics. The infrastructure is optimized for rapid deployment and evasion, typical of large-scale phishing campaigns targeting regional postal services. Evidence supporting the malicious classification includes multiple technical indicators. The domain was registered on April 27, 2026, through OwnRegistrar, Inc., a registrar frequently associated with high-risk domains. It resolves to IP address 91.202.233.133, hosted in Turkmenistan under Prospero OOO, a provider linked to bulletproof hosting services. The domain appears on three security blocklists, and Google Safe Browsing explicitly flags it as phishing. VirusTotal analysis reveals that 20 out of 95 security vendors detect the domain as malicious, with detections including credential phishing, malware distribution, and fraudulent application spoofing. The SSL certificate, issued by Let's Encrypt (R13), is valid but does not mitigate the inherent risk, as phishing sites commonly use legitimate certificates to appear trustworthy. Users who visited auspost-app.com or interacted with its content should take immediate remedial actions. Disconnect affected devices from networks to prevent lateral movement or data exfiltration. Conduct a full system scan using updated security tools to detect and remove any downloaded payloads or persistent threats. Reset credentials for any accounts accessed from the compromised device, particularly those related to financial services, email, or postal accounts. Monitor accounts for unauthorized transactions or suspicious activity. If personal or financial data was entered on the site, consider reporting the incident to relevant authorities and credit monitoring services. Infrastructure analysis reveals the domain is now offline, but users should remain vigilant for similar phishing attempts using lookalike domains or alternative delivery methods.

VirusTotal
VirusTotal
20 det.
Sertifikat TLS
Kedaluwarsa atau belum diverifikasi -32d
Usia
3 mo
Status terpantau
Terakhir diketahui aktif 200
PhishDestroy
Daftar Hapus
Terdaftar
Cakupan data VirusTotal 20 / 91 URLQuery tidak diperiksa PhishStats tidak diperiksa OTX no community references CF Radar no data URLScan capture not submitted URLScan verdict putusan tidak tersedia Pemblokiran DNS tidak diperiksa TLS Kedaluwarsa atau belum diverifikasi WHOIS 3 mo old Tangkapan layar belum terekam Rantai pengalihan tidak diselidiki

Alur Tanggapan Ancaman Pipeline

Penemuan
Checks
Reports
Ketersediaan
6/8

Status Daftar Blokir Publik

Intelijen Domain

Domain
Google Safe Browsing Ditandai MalwareSocial engineering checked 28/04/2026
Server / ASN - · AS200593 PROSPERO OOO
Reputasi IP abuse score 0/100 0 reports checked 13/07/2026
Alamat IP 91.202.233.133 TM
LokasiTM Ashgabat, TM
JaringanAS200593 · Prospero OOO
PendaftaranDibuat 27/04/2026 (104d)
Status HTTP200
Rincian teknisDNS, SAN SSL, cap waktu
Pertama Kali Terdeteksi15/06/2026
Server namamiki.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 10/04/2026scanned 27/04/2026
ICANN OVERSIGHT

Akreditasi dan konteks RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Tidak ada yang dikirim secara otomatis.
Laporkan Domain Ini Kirimkan bukti & bantu lindungi orang lain

Analisis VirusTotal

20 / Vendor keamanan 91 menandai domain ini
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
CyRadar
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Google Safebrowsing
Gridinsoft
Lionic
Netcraft
Seclookup
SOCRadar
Sophos
VIPRE
Webroot
Analisis Performa Situs

Google PageSpeed Insights — mobile performance audit of auspost-app.com · checked Apr 28, 2026

93
Good
Performance
FCP
2.56s
First Contentful Paint
LCP
2.56s
Largest Contentful Paint
CLS
0.001
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
2.56s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Bukti & Laporan Eksternal

Apakah Anda Terpengaruh oleh Situs Ini?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.

Europol
Temukan saluran pelaporan resmi untuk negara UE Anda
National police directory
Waspadalah terhadap penipu yang mengatasnamakan pemulihan! Penjahat dapat menghubungi korban lagi sambil berpura-pura menjadi penyelidik, pengacara, atau agen pemulihan. Jangan membayar biaya di muka atau membagikan kredensial. Pelajari lebih lanjut tentang penipuan dalam proses pemulihan →

Laporkan kepada Pihak Berwenang di Daerah Anda

Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.

Direktori 97 negara
Draf yang dibantu AI — detail insiden diproses oleh penyedia AI Tinjau dan kirimkan sendiri

Periksa Domain Apa Pun

Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik

Pindai Sekarang

Laporkan Phishing

Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas

Laporan

Pemberitahuan Ancaman Real-Time

Laporan phishing terbaru dan perubahan ketersediaan yang diamati

Pantau

Tetap Terinformasi, Tetap Aman

Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive

Pemberitahuan Ancaman Real-Time Ajukan Banding Terhadap Iklan Ini
HTML · IFRAME

Sematkan Laporan Ini

Bagikan informasi ancaman ini di situs web atau blog Anda

embed.html
<iframe
  src="https://phishdestroy.io/id/embed/domain/auspost-app.com"
  title="PhishDestroy threat report for auspost-app.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Surat Terima Kasih yang Sangat Tulus

Pembuat draf satir

Penerima
Konteks biaya

Draf satir. Angka biaya merupakan perkiraan; tidak diklaim bahwa angka tersebut secara tepat terkait dengan domain ini.