app-beneficios[.]dynv6[.]net
“app-beneficios.dynv6.net”
app-beneficios.dynv6.net — Conteúdo indisponível. Resumo das evidências: VirusTotal 12/93 (alphaMountain.ai, BitDefender, Certego, CRDF, CyRadar); URLQuery 2 alerts; CF Radar malicious; PhishDestroy score 86/100. Registrador: Hetzner Online.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis indicates that the domain app-beneficios.dynv6.net was registered on 21 February 2026 through Hetzner Online GmbH and is hosted on an Amazon Web Services EC2 instance in the US (us‑east‑2) at IP address 18.216.152.225. The domain resolves to this IP and relies on the dynv6.net name‑server set (ns1.dynv6.com, ns2.dynv6.net, ns3.dynv6.net). A simple HTTP request returns a page title that matches the domain name, and no additional content has been captured, suggesting the site was intended solely for credential harvesting.
The infrastructure has been listed on a single public blocklist, PhishDestroy, and the domain is currently taken offline. VirusTotal analysis shows that 12 of 93 security scanners flagged the domain as malicious, including both commercial and open‑source engines, reinforcing the suspicion of phishing use. No SSL certificate details, Safe Browsing verdicts, or Open Threat Exchange references were observed in the available intelligence.
The combination of a recent registration date, rapid blocklist inclusion, and multiple vendor detections points to a short‑lived phishing campaign that was quickly dismantled. Defenders should continue to monitor DNS resolutions for the IP address 18.216.152.225 and the associated dynv6.net name‑servers, add the domain to internal blocklists, and update web‑filtering rules to deny traffic to any sub‑domains of dynv6.net that resolve to the same AWS region. Because the site is already offline, immediate mitigation focuses on preventing reuse of the same hosting resources by related campaigns and ensuring that any residual references in email or malicious URL feeds are blocked.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo