Lompat ke laporan keamanan
⚠️
Domain ini telah ditandai sebagai berbahaya
Mesin keamanan melaporkan deteksi: 4. Berhati-hatilah — jangan memasukkan kredensial atau informasi pribadi.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
4 months
Reports sent
1
Current status
HTTP 200 at latest stored check
Keamanan domain dan intelijen ancaman

ga[.]eng[.]br

“MEGAWIN288 | Bocoran RTP Live Gacor”

Putusan ancaman Kritis 85/100 skor bukti
Ketersediaan Terselubung · dapat dijangkau Reachability diamati melalui pemeriksaan penyelubungan
Deteksi Total Virus: 4/94 URLQuery threat systems: 1 alert Jenis penipuan: Crypto Gambling Terakhir diketahui aktif
31/03/2026 1 Report Sent

Deteksi tersimpan

Peringatan penyamaran

Jenis penyamaran
content_divergence
Skor penyamaran
1/6
Judul untuk pemindaiGA Engenharia Elétrica
Judul untuk pengunjungMEGAWIN288 | Bocoran RTP Live Gacor

Ringkasan bukti

KRITIS
Evidence score
85/100

This domain, ga.eng.br, is actively engaged in credential theft and fraudulent gambling operations, specifically targeting users seeking real-time return-to-player (RTP) statistics under the guise of "MEGAWIN288 | Bocoran RTP Live Gacor." Analysis indicates the site is designed to harvest login credentials, payment details, or personal information from victims under the pretense of providing exclusive gambling insights. No direct evidence of a crypto drainer kit was observed, but the combination of credential theft and gambling fraud suggests a multi-stage monetization strategy, likely involving unauthorized access to user accounts or financial instruments. Infrastructure analysis reveals the domain resolves to IP address 162.241.2.208 and was registered on March 31, 2026, an anomalous creation date that may indicate domain spoofing or a typo-squatting attempt. The domain is flagged by 12 out of 95 security vendors on VirusTotal, with a Gridinsoft trust score of 0/100. It appears on one security blocklist and is currently blocked by PhishDestroy. The site employs a Let's Encrypt SSL certificate, which, while providing encryption, is commonly abused by malicious actors due to its low-barrier issuance process. Detected technologies include Shopify, Apache HTTP Server, AMP, Slick, jQuery, and BugSnag, suggesting a templated or kit-based deployment rather than a custom-built infrastructure. The domain remains active and poses an elevated risk to users, particularly those in gambling or cryptocurrency communities. Immediate response actions should include blacklisting the domain and IP across security gateways, notifying the registrar of abusive activity, and alerting financial institutions to monitor for fraudulent transactions linked to this campaign. Users are advised to avoid interacting with the domain, reset credentials for any accounts accessed via the site, and verify the legitimacy of any gambling or financial platforms through official channels. The anomalous creation date and low detection rate among security vendors underscore the need for heightened vigilance, as this campaign may evade traditional detection mechanisms.

Snapshot bukti yang dikirim

Dikirim
Catatan buku besar
1
ID kasus
PD-20260331-5777CF
Judul halaman yang direkam
Secure access · SharePoint
Artefak PDF
Bukti PDF
Teks bukti lengkap
Policy Violations:
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (BR):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and BR's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
VirusTotal
VirusTotal
4 det.
URLQuery
URLQuery
1 threat alert
DNS Security
5/12
Sertifikat TLS
Let's Encrypt
Usia
4 mo
Status terpantau
Terselubung · dapat dijangkau HTTP 200
PhishDestroy
Daftar Hapus
Terdaftar
Reports Sent
1

Data Coverage

VirusTotal 4 / 94 URLQuery 1 threat-system alert PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture laporan yang disimpan URLScan verdict Analisis selesai Pemblokiran DNS 5/12 TLS valid certificate, 59d WHOIS 4 mo old Tangkapan layar 3 captures · 3 sources Rantai pengalihan tidak diselidiki
Intelijen Keamanan Jaringan
DNS Provider Blocks 5 / 12
Adguard Default Adguard Family Controld Adblock Controld Family Controld Malware
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
Hagezi Threat Feed ga.eng.br malicious Sinkholed

Alur Tanggapan Ancaman Pipeline

Penemuan
Checks
Reports
Ketersediaan
11/12

Cakupan daftar blokir

10 sumber eksternal dipantau · snapshot tersimpan 11/08/2026

10 sumber eksternal dipantau Tidak cocok

Linimasa deteksi

  1. VirusTotal

    4 → 12

Tangkapan tersimpan

Intelijen Domain

Domain
URLScan Verdict Analisis selesai score 0 report ↗
Server / ASN Apache · AS31898 Oracle Corporation
Reputasi IP IP abuse confidence 0/100 0 reports checked 14/07/2026
Registrar Tidak diketahui BR(BR)
Kontak penyalahgunaanabuse@bluehost.com
Alamat IP 162.241.2.208 BR
LokasiBR Vinhedo, BR
JaringanAS31898 · Unified Layer
PendaftaranDibuat 31/03/2026 (132d) Expires 03/03/2027
Elapsed Since First Report 14h
Yang kami hitung Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Terselubung · dapat dijangkau.
Isi setiap laporan Catatan laporan keluar yang disimpan dapat merujuk pada bukti yang tersedia pada saat itu, seperti keputusan vendor, data pendaftaran, detail hosting, klasifikasi, atau tangkapan layar. Halaman ini tidak menyimpulkan secara pasti muatan yang dikirimkan, penerimaan, pengakuan, atau tindakan oleh penerima.
Status HTTP200
Detail teknisDNS, nama TLS, dan stempel waktu
Pertama Kali Terdeteksi31/03/2026
Submitted URLhttp://ga.eng.br/RisingAboveMinistry/rhondashort.html
Server namans516.hostgator.com.brns517.hostgator.com.br
Sidik jari TLS
Pengamatan TLSberlaku sejak 26/03/2026dipindai 23/04/2026
Nama alternatif subjek TLSautodiscover.ga.eng.brcpanel.ga.eng.brcpcalendars.ga.eng.brcpcontacts.ga.eng.brmail.ga.eng.brwebdisk.ga.eng.brwebmail.ga.eng.brwww.ga.eng.br
Favicon Hash
Judul Halaman
MEGAWIN288 | Bocoran RTP Live Gacor
Sertifikat TLS
Valid transport encryption · Diterbitkan oleh Let's Encrypt · valid for 59 days
Casino / Gambling License Verification
Unverified gambling license
This domain markets casino/gambling services. Scam casinos routinely display fake Curaçao, MGA, or Kahnawake license badges that don’t exist in the real registries. Always verify the license number against the official regulator database before depositing. If the site shows a seal but no clickable registry link — or the linked registry page doesn’t exist — treat it as fraudulent.
Curaçao eGaming (official) Malta Gaming Authority UK Gambling Commission PA Gaming Control Kahnawake Gaming Gibraltar Gambling
Laporkan Domain Ini Kirimkan bukti & bantu lindungi orang lain

Analisis VirusTotal

4 / Vendor keamanan 94 menandai domain ini
View on VT
Last analyzed
alphaMountain.ai
CRDF
Gridinsoft
SOCRadar
Analisis Performa Situs

Google PageSpeed Insights — mobile performance audit of ga.eng.br · checked Jun 26, 2026

68
Needs Work
Performance
FCP
3.38s
First Contentful Paint
LCP
3.68s
Largest Contentful Paint
CLS
0.201
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
6.03s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Apakah Anda Terpengaruh oleh Situs Ini?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.

Europol
Temukan saluran pelaporan resmi untuk negara UE Anda
National police directory
Waspadalah terhadap penipu yang mengatasnamakan pemulihan! Penjahat dapat menghubungi korban lagi sambil berpura-pura menjadi penyelidik, pengacara, atau agen pemulihan. Jangan membayar biaya di muka atau membagikan kredensial. Pelajari lebih lanjut tentang penipuan dalam proses pemulihan →

Laporkan kepada Pihak Berwenang di Daerah Anda

Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.

Direktori 97 negara
Draf yang dibantu AI — detail insiden diproses oleh penyedia AI Tinjau dan kirimkan sendiri

Periksa Domain Apa Pun

Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik

Pindai Sekarang

Laporkan Phishing

Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas

Laporan

Pemberitahuan Ancaman Real-Time

Laporan phishing terbaru dan perubahan ketersediaan yang diamati

Pantau

Tetap Terinformasi, Tetap Aman

Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive

Pemberitahuan Ancaman Real-Time Ajukan Banding Terhadap Iklan Ini

Alat eksternal

HTML · IFRAME

Sematkan Laporan Ini

Bagikan informasi ancaman ini di situs web atau blog Anda

embed.html
<iframe
  src="https://phishdestroy.io/id/embed/domain/ga.eng.br"
  title="PhishDestroy threat report for ga.eng.br"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>