vfindermagazine[.]com
“Aplikasi Login Pengguna”
Riepilogo delle prove
The domain vfindermagazine.com was registered through BigRock Solutions Ltd. on July 27, 2024 and is currently listed as offline. Infrastructure analysis shows the domain resolves to IP address 157.20.51.78, which belongs to AS140641 YOTTA NETWORK SERVICES PRIVATE LIMITED and is geolocated in India. The authoritative nameservers are ns1.compliance2win.com and ns2.compliance2win.com, indicating a possible shared hosting environment with other compliance‑related sites. The site presented the page title "Aplikasi Login Pengguna," which aligns with the observed credential phishing classification.
A Let's Encrypt R12 certificate was observed, providing HTTPS encryption but offering no assurance of legitimacy. VirusTotal records indicate that 12 of 95 scanning engines flagged the domain, reinforcing the suspicion of malicious activity. The domain appears on a single public blocklist and is actively blocked by PhishDestroy, suggesting that at least one security vendor has taken mitigation steps.
While the exact phishing kit or targeted brand is not disclosed, the combination of a credential‑focused page title, multiple vendor detections, and blocklist presence points to a credential harvesting campaign. Defenders should continue to block the domain at perimeter defenses, monitor DNS queries for the IP address 157.20.51.78, and update URL filtering policies to include the associated nameservers. Given the domain's offline status, ongoing observation is recommended to detect any re‑hosting attempts or related infrastructure that may be leveraged in future campaigns.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Stato del dominio
Non raggiungibile → Raggiungibile
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo