aktifkaanpaylattersx[.]lhc[.]my[.]id
“DANA - Apa pun transaksinya selalu ada DANA”
aktifkaanpaylattersx.lhc.my.id — Контент недоступен. Олицетворение бренда: DANA; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 20/95 (ADMINUSLabs, BitDefender, Cluster25, CRDF, CyRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 100/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis indicates that the domain aktifkaanpaylattersx.lhc.my.id is active and associated with the brand_impersonation threat category. The observed page title matches the impersonated brand, DANA, indicating an attempt to imitate a legitimate online service. No drainer kit information is available from the supplied intelligence. The combination of impersonation indicators, active status, and infrastructure characteristics supports an elevated risk assessment for credential theft or fraudulent transaction workflows.
Technical indicators identify a VirusTotal detection score of 20/95 security vendors. The domain is registered through Cloudflare, Inc. and resolves to IP address 172.67.213.143, located in the US within AS13335 Cloudflare, Inc. No creation date is available from the provided intelligence. The domain has no SSL certificate, appears on 1 security blocklist, and has been blocked by PhishDestroy. These indicators collectively demonstrate externally observed malicious or suspicious behavior consistent with brand impersonation infrastructure.
The domain remains active at the time of assessment, leaving residual exposure for users who encounter links directing to this infrastructure. Recommended response actions include immediate blocking at network, DNS, email, and web gateway layers, continued monitoring for infrastructure changes, and preservation of relevant indicators for incident response and threat hunting. Any interaction with the site should be considered potentially unsafe until independent verification confirms otherwise. The absence of an SSL certificate does not reduce the operational risk, while the existing detection coverage and blocklist presence reinforce the elevated likelihood of malicious use.
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание