rafstaffing[.]com
“World news – e-enable synergistic initiatives”
Resumo das evidências
Analysis of rafstaffing.com indicates this domain was actively used for banking phishing operations until its recent takedown. The domain was registered on February 21, 2026, and resolved to IP address 5.42.65.101, hosted on AS39493 (CJSC Kolomna-Sviaz TV) in Russia. Infrastructure analysis reveals a Gridinsoft trust score of 0/100, and the domain appears on at least one security blocklist, including PhishDestroy. AlienVault OTX records show the domain in two threat intelligence pulses, confirming its inclusion in broader phishing campaigns. The SSL certificate is issued by R3, a common certificate authority, which provides no additional indicators of compromise but aligns with typical phishing infrastructure.
The page title, 'World news – e-enable synergistic initiatives,' does not explicitly reveal the targeted brand or institution, though the scam type is classified as banking phishing based on available intelligence. As of July 24, 2026, the domain is offline, likely due to enforcement action or infrastructure changes. One of 95 security vendors on VirusTotal flagged the domain prior to its takedown, though this detection rate is not conclusive evidence of its malicious nature. No further details about the phishing kit, targeted financial institutions, or specific attack vectors are available in the current data.
Defenders should treat this domain as confirmed malicious for banking-related phishing. Network-level blocking of 5.42.65.101 and monitoring for related domains registered under the same ASN or registrar is recommended. Security teams should review logs for connections to rafstaffing.com or its resolved IP, particularly from endpoints accessing financial services. If the domain reappears under a new IP or with altered infrastructure, additional scrutiny is warranted due to its prior association with phishing activity.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência forense
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo