bbwukjih[.]dnq[.]r[.]110880[.]cn
“TikTok”
bbwukjih.dnq.r.110880.cn — Konten tidak tersedia. Peniruan identitas merek: TikTok; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 17/93 (Criminal IP, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 95/100. Registrar: Dynadot.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis indicates that the domain bbwukjih.dnq.r.110880.cn was registered on August 2, 2025 through Dynadot LLC and is currently taken offline. The domain resolves to the IPv4 address 38.46.13.34, which is announced by AS9294 GNET INC. and geolocated to Hong Kong. No TLS certificate is presented, meaning the site would have been served over plain HTTP only. The page title returned from the host is “TikTok”, matching the declared brand target of TikTok and confirming a brand‑impersonation motive.
Google Safe Browsing has flagged the domain for social engineering, and Gridinsoft assigns a trust score of 0 out of 100, indicating a high likelihood of malicious intent. VirusTotal reports that 17 out of 93 scanning engines have identified the domain as malicious, reinforcing the suspicion. The domain is listed on a single security blocklist and has been actively blocked by PhishDestroy. Nameserver records point to ns1.dnsip.com and ns2.dnsip.com, which are commonly used by disposable or fast‑flux services.
The combination of a recent registration, lack of encryption, low trust score, multiple vendor detections, and explicit brand targeting provides concrete evidence that the domain was employed for brand‑impersonation attacks against TikTok users. Uncertainty remains regarding the exact payload or credential‑harvesting mechanisms because the site content has not been captured; however, the existing indicators are sufficient for defensive actions. Organizations should add the domain to internal blocklists, monitor DNS queries for the associated IP and nameservers, and ensure that web filtering solutions incorporate the Google Safe Browsing and PhishDestroy classifications. Continuous re‑scanning of the IP address is advised in case the domain becomes active again.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive