riren-yyaaa-aaaag-alf5q-cai[.]icp0[.]io
“Shibarium Intake From”
riren-yyaaa-aaaag-alf5q-cai.icp0.io — Belum terverifikasi. Ringkasan bukti: VirusTotal 4/91 (alphaMountain.ai, Chong Lua Dao, Gridinsoft, LevelBlue); 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 78/100. Registrar: GoDaddy.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain riren-yyaaa-aaaag-alf5q-cai.icp0.io is a generic phishing site that does not impersonate any specific brand and does not use a known crypto drainer kit. It was observed with the page title 'Shibarium Intake From', indicating it likely targeted users of the Shibarium ecosystem. The site is currently taken offline, meaning it is no longer accessible and poses no active threat.
Technical analysis shows that riren-yyaaa-aaaag-alf5q-cai.icp0.io was flagged by 1 of 95 VirusTotal vendors, including Trustwave, and appears on 3 security blocklists: PhishDestroy, ScamSniffer, and Enkrypt. The domain was registered through GoDaddy.com, LLC on September 06, 2022, and resolves to IP address 2602:fb2b:110:1:bcfb:b8ff:fe09:c741, located in Germany (AS398485 DFINITY USA Research, LLC). It uses an SSL certificate issued by Let's Encrypt / E7 and is hosted on Cloudflare with HSTS and cdnjs technologies. Google Safe Browsing did not flag the domain, and the HTTP status was 503 at the time of analysis.
Users who interacted with riren-yyaaa-aaaag-alf5q-cai.icp0.io should take immediate safety steps. Since this is a generic phishing site without a specific drainer, but with a title referencing Shibarium, it likely attempted to steal login credentials or personal information. Affected individuals should change passwords for any accounts entered on the site, enable two-factor authentication (2FA) on those accounts, and monitor for unauthorized activity. To report the domain, submit it to security blocklists like PhishDestroy or ScamSniffer, and file a complaint with the Internet Crime Complaint Center (IC3) if financial loss occurred.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 4 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comHTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
“Angel drainer”
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive