sspl[.]com[.]aucom[.]auwww[.]mail7[.]sspl[.]com[.]auwww[.]com[.]auwww[.]mail7[.]sspl[.]com[.]aucom[.]auwww[.]mail7[.]sspl[.]com[.]au
“Index of /”
sspl.com.aucom.auwww.mail7.sspl.com.auwww.com.auwww.mail7.sspl.com.aucom.auwww.mail7.sspl.com.au — Belum terverifikasi. Peniruan identitas merek: Google; Jenis penipuan: Impersonation. Ringkasan bukti: VirusTotal 12/91 (AILabs (MONITORAPP), BitDefender, ESET, Forcepoint ThreatSeeker, Fortinet); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 98/100. Registrar: Web Address Registrati….
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis indicates that the domain sspl.com.aucom.auwww.mail7.sspl.com.auwww.com.auwww.mail7.sspl.com.aucom.auwww.mail7.sspl.com.au is currently offline but was previously hosting content that returned HTTP 200 with the generic directory listing page title “Index of /”. The domain is registered through Web Address Registration Pty Ltd and resolves to the IPv4 address 185.184.154.169, which is announced by AS38719 Dreamscape Networks Limited in Australia. The hosting environment uses nameservers ns1.vodien.com, ns2.vodien.com and ns3.vodien.com, and the site presented a valid Let’s Encrypt R12 certificate, suggesting the use of automated certificate provisioning. The infrastructure was flagged by multiple security services: Google Safe Browsing categorizes the site as social engineering, and VirusTotal recorded 14 detections out of 95 scanned engines. The domain appears on one public blocklist and was actively blocked by the PhishDestroy feed.
Gridinsoft assigned a trust score of zero out of one hundred, reinforcing the malicious assessment. The threat profile identifies the campaign as a high‑risk brand impersonation targeting Google, consistent with the reported impersonation flag. The presence of an active Let’s Encrypt certificate indicates that the operators had the capability to obtain legitimate‑looking TLS, which can aid in bypassing naïve user trust checks. The HTTP 200 response combined with the directory index title suggests that no specific phishing page was captured at the time of analysis, but the infrastructure was clearly prepared for malicious content delivery.
While the site is no longer reachable, the observed indicators remain useful for correlation. Defenders should continue to monitor the IP address 185.184.154.169 and the associated nameserver set for reuse, enforce blocklisting of the domain in web filters, and incorporate the TLS certificate fingerprint into detection rules.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti Terarsip
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of sspl.com.aucom.auwww.mail7.sspl.com.auwww.com.auwww.mail7.sspl.com.aucom.auwww.mail7.sspl.com.au · checked Mar 2, 2026
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive