lookdotfun[.]info
Pemeriksaan phishing dan keamanan lookdotfun.info
“Lovable App”
lookdotfun.info — Dapat dijangkau · akses dibatasi (HTTP 403). Peniruan identitas merek: Instagram; Jenis penipuan: Crypto Drainer. Ringkasan bukti: VirusTotal 9/93 (ADMINUSLabs, alphaMountain.ai, CyRadar, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 77/100. Registrar: NiceNIC.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain lookdotfun.info was registered on February 21, 2026 through NiceNIC International Group Co., Limited and is currently reported as taken offline. Infrastructure analysis reveals that the domain resolves to the Cloudflare‑owned address 172.67.135.68, located in the United States and advertised under AS13335 Cloudflare, Inc. The DNS configuration uses the Cloudflare nameservers carol.ns.cloudflare.com and bryce.ns.cloudflare.com, and the site served an HTTPS certificate issued by Let’s Encrypt (E8). HTTP responses return a 403 status code, and the site advertised the page title “Lovable App”. Technical fingerprints include HSTS, Cloudflare Browser Insights, and HTTP/3 support, indicating a modern CDN deployment.
Brand‑targeting evidence shows the domain impersonates Instagram and is classified as a Wallet/Seed phishing campaign. Detection services have flagged the domain: nine of ninety‑three VirusTotal scanners identified malicious activity, and the domain appears on three external blocklists. Additional protective services—PhishDestroy, MetaMask, and SEAL—have listed the site as blocked. Reputation scoring from Gridinsoft assigns a 0 out of 100 trust score, reinforcing the malicious assessment.
While the site is offline, the available telemetry confirms a concerted effort to harvest cryptocurrency wallet seeds under the guise of an Instagram‑related service. Defenders should update URL filtering rules to include lookdotfun.info, monitor for any resurgence of the domain or associated IP ranges, and enforce strict verification of SSL certificates for any similar Cloudflare‑hosted domains. Network sensors should be tuned to detect outbound connections to the 172.67.135.68 address, and endpoint solutions should flag any attempts to submit seed phrases to URLs matching the observed page title pattern. Continuous re‑evaluation is advised in case the infrastructure is re‑hosted or the domain is re‑registered for future campaigns.
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:06:36 UTC
Teknologi · 4 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive