digitalrakuten[.]com
digitalrakuten.com için kimlik avı ve güvenlik kontrolü
“One moment, please...”
digitalrakuten.com — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Rakuten; Dolandırıcılık türü: E Commerce Scam. Kanıt özeti: VirusTotal 18/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 4 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Kayıt kuruluşu: GMO Internet Group.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies digitalrakuten.com as a fake login phishing page impersonating Rakuten, a major Japanese e-commerce platform. The domain was registered through GMO Internet, Inc. on March 20, 2026, and currently resolves to IP 118.27.146.17. The threat actor behind this domain appears to be using it to harvest user credentials under the guise of a legitimate Rakuten login portal, likely to gain unauthorized access to accounts for financial theft or further fraudulent activity. The domain is associated with a crypto drainer kit, designed to siphon cryptocurrency assets from compromised wallets or accounts once login credentials are obtained.
The domain exhibits multiple red flags across technical and behavioral indicators. PhishDestroy’s forensic analysis reveals that 11 out of 95 security vendors on VirusTotal have flagged digitalrakuten.com as malicious, indicating broad recognition of its threat potential. The domain was registered through GMO Internet, Inc., a legitimate registrar, but the timing and context of its creation (March 20, 2026) suggest a recent and opportunistic campaign. It resolves to IP 118.27.146.17, which hosts multiple suspicious domains and has been flagged in various threat intelligence feeds. The domain obtained an SSL certificate from Let’s Encrypt, a tactic commonly used by threat actors to lend an air of legitimacy to phishing pages. Additionally, digitalrakuten.com is not listed in Google Safe Browsing (GSB) and has been identified in 12 public blocklists, further confirming its malicious nature.
As of the latest analysis, digitalrakuten.com remains active and continues to pose an elevated risk to unsuspecting users. PhishDestroy has added this domain to its real-time blocklist, and security teams are actively monitoring its infrastructure for changes. However, the domain’s recent creation and the use of a legitimate SSL certificate mean it may evade detection by less sophisticated security tools. Users are strongly advised to avoid interacting with digitalrakuten.com and verify any suspicious links using PhishDestroy’s verification tools. The remaining risk is elevated due to the domain’s active status and the potential for it to be used in broader phishing campaigns targeting Rakuten users. Immediate action is required to prevent credential theft and financial loss.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | digitalrakuten.com |
malicious | Sinkholed |
| OpenDNS | digitalrakuten.com |
phishing | Phishing Block |
| DigiCert UltraDNS | digitalrakuten.com |
malicious | Sinkholed |
| DNS4EU | digitalrakuten.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler · 2 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of digitalrakuten.com · checked Mar 28, 2026
Kanıtlar ve Dış Raporlar
PD-20260328-7A1E2D Recipient: abuse@internet.gmo Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin