rndex[.]ink
“404 Not Found”
rndex.ink — Não verificado. Resumo das evidências: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar, Gridinsoft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain rndex.ink was registered on 21 February 2026 and resolves to the Cloudflare address 104.21.17.188, which is owned by AS13335 Cloudflare, Inc. and located in the United States. The authoritative name servers are sandra.ns.cloudflare.com and arvind.ns.cloudflare.com, confirming that the site is using Cloudflare DNS and CDN services. An SSL certificate identified as “WE1” is present, indicating that TLS is configured, but the certificate details provide no indication of legitimate ownership. Automated analysis on VirusTotal shows that 2 of 93 security vendors have flagged rndex.ink as malicious, and the domain appears on three independent security blocklists.
Independent blocklist providers PhishDestroy, MetaMask, and SEAL have already added the domain to their deny lists. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the malicious assessment. When accessed, the HTTP response returns the title “404 Not Found”, suggesting that the site is currently offline or deliberately serving an error page. The current operational status is reported as offline, and no additional content has been captured.
Because the page content, phishing kit, or targeted brand have not been disclosed, the precise phishing vector remains unknown. However, the combination of recent registration, Cloudflare hosting, low trust score, and vendor detections aligns with typical infrastructure used for credential‑harvesting campaigns. Defenders should continue to block rndex.ink at network perimeter and DNS resolvers, monitor for any re‑activation of the host, and consider adding the associated IP address 104.21.17.188 to deny lists, noting that this IP is shared by many legitimate Cloudflare customers. Ongoing threat intelligence feeds should be consulted for any future observations that might reveal the phishing payload or target audience.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo