sites[.]it-safe[.]web[.]id
“Copyright Infringement”
sites.it-safe.web.id — Encoberto · alcançável. Representação da marca: Facebook; Tipo de golpe: Impersonation. Resumo das evidências: VirusTotal 16/91 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, CRDF); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 100/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, sites.it-safe.web.id, is flagged as a generic_phishing threat designed to mimic copyright infringement notices. Analysis indicates the page title explicitly states 'Copyright Infringement,' suggesting an attempt to deceive users into believing they are interacting with a legitimate legal enforcement mechanism. No specific brand impersonation or drainer kit signatures were identified, though the tactic aligns with common phishing campaigns targeting intellectual property violations. The domain lacks branding elements, relying instead on urgency and fear to manipulate victims. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc., and currently resolves to the IP address 188.114.97.3, hosted on AS13335 (Cloudflare, Inc.) in the United States. The domain holds no valid SSL certificate, increasing the likelihood of interception or manipulation of unencrypted traffic. VirusTotal reports 22 out of 95 security vendors flagging the domain as malicious, while it appears on one security blocklist. No creation date or Google Safe Browsing (GSB) status was provided, though the absence of SSL and the use of Cloudflare infrastructure are consistent with ephemeral phishing operations. The domain has been taken offline, reducing immediate risk to users. However, the infrastructure remains registered under Cloudflare, and the threat actor may redeploy the domain or spin up similar variants. Response actions include blocking the domain via PhishDestroy and monitoring for re-emergence or related indicators. Remaining risk includes potential reuse of the IP or registrar for future phishing campaigns. Organizations are advised to update blocklists with the domain and IP, conduct retrospective log analysis for connections to 188.114.97.3, and educate users on recognizing fraudulent copyright enforcement schemes.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo