rbi-in[.]org
“rbi-in.org”
Kanıt özeti
Analysis of rbi-in.org, which was taken offline as of the report date, shows a recent registration (13 Feb 2025) through Sav.com, LLC and resolution to IP 198.251.89.164 in the United States, announced by AS53667 FranTech Solutions. The domain is served by LiteSpeed with HTTP/3 support and presents a Let's Encrypt E8 certificate, indicating a valid TLS handshake at the time of observation. DNS records list ns13.my‑control‑panel.com and ns14.my‑control‑panel.com as authoritative nameservers and a single mail exchanger (priority 10) pointing to mail.rbi-in.org. The page title returned simply mirrors the domain name, offering no additional context about the hosted content.
Threat intelligence indicates that the domain appears on four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—signalling consensus among anti‑phishing services that the site was used for malicious purposes. VirusTotal scanning recorded a single positive detection out of ninety‑five vendors, providing concrete vendor‑level corroboration of malicious activity. While the exact phishing payload or targeted brand has not been disclosed, the classification as generic phishing aligns with the observed infrastructure and blocklist listings.
Uncertainty remains regarding the specific campaign timeline, victim demographics, and whether any residual infrastructure (e.g., subdomains or credential‑harvesting endpoints) persists after the takedown. Defensive recommendations include adding 198.251.89.164 to network deny lists, enforcing DNS filtering for the domain and its associated MX record, monitoring for any resurgence of the domain or its nameservers, and updating email security gateways to reject messages from mail.rbi-in.org. Continuous threat‑intel feeds should be consulted for any re‑registration attempts, and security teams should treat the domain as a high‑confidence phishing indicator despite the limited detection count.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
7 izlenen harici kaynak Eşleşme yok
Tespit zaman çizelgesi
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
Alan adı durumu
Erişilemiyor → Erişilebilir
Topluluk raporları
1 topluluk üyesi tarafından bildirildi; ilk görülme 18.08.2025
- Kayıtlı raporlar
- 1
- Bildirilen benzersiz URL’ler
- 1
Topluluk istihbaratı
1 topluluk raporu
KategoriPHISHING
Blacklist from Phishfort
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin