aktivpayletter[.]safetycs[.]biz[.]id
“𝗗𝗔𝗡𝗔 𝗜𝗗 | 𝗔𝗸𝘁𝗶𝗳𝗸𝗮𝗻 𝗙𝗶𝘁𝘂𝗿”
aktivpayletter.safetycs.biz.id — Doğrulanmamış. Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 14/91 (BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet); CF Radar malicious; PhishDestroy score 97/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, aktivpayletter.safetycs.biz.id, poses as a legitimate DANA ID activation portal to harvest user credentials and financial information. The page title, "𝗗𝗔𝗡𝗔 𝗜𝗗 | 𝗔𝗸𝘁𝗶𝗳𝗸𝗮𝗻 𝗙𝗶𝘁𝘂𝗿," mimics the official Indonesian digital wallet service, tricking users into entering sensitive login details or payment information. The infrastructure is designed to appear authentic, leveraging Cloudflare’s content delivery network to obscure its true origin and evade basic security filters. Analysis indicates the domain is registered through Cloudflare, Inc., and resolves to the IP address 188.114.97.3, located in the United States under AS13335 (Cloudflare, Inc.). Security vendors have flagged it as malicious, with 18 out of 95 engines on VirusTotal detecting it as phishing infrastructure. Additionally, the domain appears on two security blocklists, including PhishDestroy and PhishingDB, further confirming its malicious intent. The SSL certificate, issued by Google Trust Services (WE1), adds a layer of legitimacy to the fraudulent site, increasing the likelihood of user deception. Users who visited aktivpayletter.safetycs.biz.id should immediately revoke any entered credentials and monitor their financial accounts for unauthorized activity. If login details or payment information were submitted, affected individuals should change passwords for all associated accounts and enable multi-factor authentication where available. Browser data, including cookies and cached files, should be cleared to remove any residual tracking mechanisms. Organizations are advised to block the domain and its resolving IP (188.114.97.3) at the network level to prevent further access by employees or customers.
Güvenlik Sinyalleri
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Arşivlenmiş Kanıtlar
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin