celestiadao[.]app
“BONANZASLOT: KPK Luncurkan Aplikasi dengan RTP Gacor Auto Win Modal Kecil WD Besar Anti Korup!”
Ringkasan bukti
Analysis of the domain celestiadao.app, observed as offline as of the report date, shows infrastructure consistent with a brand‑impersonation campaign targeting the Celestia brand. The domain resolves to the IP address 198.54.120.178, which belongs to the AS22612 Namecheap, Inc. network located in the United States. Registration details list NameCheap, Inc. as the registrar and the authoritative nameservers dns1.namecheaphosting.com and dns2.namecheaphosting.com, a common configuration for disposable or fast‑flux domains. No TLS certificate was presented, meaning the site would have been served over plain HTTP, a characteristic often exploited to avoid the cost of certificate acquisition.
The sole page retrieved before takedown carried the title “BONANZASLOT: KPK Luncurkan Aplikasi dengan RTP Gacor Auto Win Modal Kecil WD Besar Anti Korup!” which bears no obvious relation to the Celestia brand, indicating the page content has not been publicly verified. The domain is classified as a brand‑impersonation scam and marked as impersonating Celestia. Security‑vendor aggregators have identified the site as malicious: Gridinsoft assigned a trust score of 0 / 100, one security blocklist lists the domain, and nine of ninety‑five VirusTotal scanners flagged it as malicious. The blocklist PhishDestroy also actively blocks the domain.
Given the limited public artifacts, the exact phishing vector (e.g., credential‑harvesting page, malicious download) remains uncertain. Defenders should block network traffic to 198.54.120.178 and to the domain name itself at DNS and proxy layers. Email filters should add celestiadao.app to malicious sender lists, and SOC analysts should monitor for any references to the Celestia brand in outbound traffic that resolve to the same IP range. Continuous re‑scanning of the domain after it reappears is advised, as the lack of SSL and the use of a generic hosting provider suggest the site could be rapidly redeployed with new content.
Data Coverage
Sinyal Keamanan
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 11/08/2026
Linimasa deteksi
-
Cloudflare Radar
Pemindaian Cloudflare Radar tersimpan · Buka pemindaian
Tangkapan tersimpan
Intelijen Domain
Detail teknisDNS, nama TLS, dan stempel waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive