pub-321ad47684174ff88663e8553aab91d7[.]r2[.]dev
“DANATOTO : Platform Permainan Slot Online Gacor Terkemuka & Slot Qris 5000 Gampang Menang”
pub-321ad47684174ff88663e8553aab91d7.r2.dev — İçerik kullanılamıyor. Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 1/91 (alphaMountain.ai); PhishDestroy score 55/100. Kayıt kuruluşu: Cloudflare R2.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain is flagged as a confirmed generic phishing site hosting malicious content designed to deceive users. The infrastructure leverages Cloudflare R2 storage, a legitimate cloud service, to distribute phishing payloads while obscuring the true origin through a subdomain-based delivery mechanism. The site remains active with no detections recorded across 95 VirusTotal engines, suggesting evasion of current signature-based defenses. Analysis indicates this domain resolves to IP address 104.18.54.45, which is associated with Cloudflare’s edge network. The domain was registered via Cloudflare R2, a storage service, and shows no recorded detections on VirusTotal as per the latest scan. The IP address has not been identified on any known blocklists or threat intelligence feeds at this time, and no historical reputation scores are available. The lack of detection suggests a low-profile operation still in active deployment phase. Mitigation requires immediate action from network defenders. Organizations should block the domain at DNS and firewall levels using the exact string pub-321ad47684174ff88663e8553aab91d7.r2.dev and the associated IP 104.18.54.45. Users interacting with this domain should be warned of potential credential theft risks. Further investigation is required to identify the specific lure content and lures used in this campaign. This domain should be treated as an active threat vector pending additional intelligence or remediation.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin