incentrbfcustagingnet[.]azurewebsites[.]net
“Login - RBFCU STAR”
incentrbfcustagingnet.azurewebsites.net — Conteúdo indisponível. Representação da marca: Rbfcu; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 16/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 1 alert; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Registrador: Microsoft Azure.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain incentrbfcustagingnet.azurewebsites.net was registered on March 24, 2026 through Microsoft Azure and is hosted on a Microsoft Azure App Service instance in the southcentralus region (IP 40.74.255.112, United States). The site presented a login page titled "Login - RBFCU STAR" and was identified as a credential phishing operation targeting RBFCU customers. Infrastructure analysis shows the service runs on Windows Server with IIS, employs ASP.NET, and serves front‑end assets from Bootstrap, jQuery UI, jQuery CDN, Modernizr, and Cloudflare. The SSL certificate is issued by Microsoft Corporation under the Microsoft Azure RSA TLS Issuing CA 04 chain, confirming the use of Azure’s default certificate provisioning.
Security tooling indicates the domain appears on a single blocklist and has been flagged by 16 of 94 vendors on VirusTotal. Independent trust rating services assigned extremely low scores: Gridinsoft 0/100 and Scamadviser 1/100. PhishDestroy has explicitly blocked the domain. No nameserver records were returned, and the site has been taken offline at the time of this report.
Defenders should treat any traffic to this host as malicious. Immediate actions include blocking the IP address 40.74.255.112 at perimeter firewalls, updating DNS blocklists to include the fully qualified domain name, and surveilling outbound connections from internal hosts that may have attempted credential submission. Incident response teams should search for RBFCU credential exposure in logs, reset any compromised accounts, and advise affected users to change passwords. Continuous monitoring of Azure App Service IP ranges is recommended, as the attacker leveraged legitimate cloud infrastructure to lend credibility to the phishing page.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | incentrbfcustagingnet.azurewebsites.net |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Tecnologias · 13 identified
Popular CSS framework for responsive, mobile-first web development.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comLegacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Icon font library.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of incentrbfcustagingnet.azurewebsites.net · checked Mar 24, 2026
Evidências e relatórios externos
PD-20260324-11076A Recipient: abuse@microsoft.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo