dfr659[.]it
dfr659.it için kimlik avı ve güvenlik kontrolü
“Sorry, the website has been stopped”
dfr659.it — Bilinen son aktif (HTTP 200). Marka kimliğine bürünme: Genericcrypto; Dolandırıcılık türü: Impersonation. Kanıt özeti: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 100 det.; URLScan malicious verdict; 1 external blocklist match (ScamSniffer); PhishDestroy score 100/100. Kayıt kuruluşu: Dynadot.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of the domain dfr659.it indicates a high-risk phishing infrastructure currently active as of July 23, 2026. The domain was registered on November 7, 2025, through Dynadot LLC and resolves to the IP address 172.67.157.152, hosted on Cloudflare's network (AS13335). The site returns an HTTP 200 status with the page title 'Sorry, the website has been stopped,' a pattern often observed in phishing domains attempting to evade detection while maintaining operational backend systems. Infrastructure analysis reveals the use of Cloudflare services, including HSTS and HTTP/3, alongside Vue.js and Cloudflare Browser Insights, suggesting a modern web framework likely employed to facilitate malicious activity.
The domain appears on two security blocklists, including PhishDestroy and ScamSniffer, and is flagged by 16 of 93 security vendors on VirusTotal, reinforcing its classification as malicious. Gridinsoft assigns a trust score of 0/100, further corroborating the high-risk assessment. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the threat, as phishing sites frequently leverage valid certificates to appear legitimate. Nameservers are configured under Cloudflare (aria.ns.cloudflare.com and arturo.ns.cloudflare.com), a common tactic to obscure hosting details and complicate takedown efforts.
While the exact phishing campaign or targeted brand remains unconfirmed due to the generic page title, the domain's infrastructure and detection history align with known phishing operations. Defenders should treat this domain as actively malicious and prioritize blocking it at the network and endpoint levels. Monitoring for related domains registered through Dynadot or resolving to Cloudflare's IP ranges may help identify additional threats. Given the domain's persistence and detection by multiple vendors, further investigation into its backend connections and potential affiliate networks is recommended.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 5 identified
Progressive JavaScript framework for building user interfaces.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of dfr659.it · checked Mar 1, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin