aktifkaanpaylattersx[.]lhc[.]my[.]id
“DANA - Apa pun transaksinya selalu ada DANA”
aktifkaanpaylattersx.lhc.my.id — Контент недоступний. Уособлення бренду: DANA; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 20/95 (ADMINUSLabs, BitDefender, Cluster25, CRDF, CyRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 100/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis indicates that the domain aktifkaanpaylattersx.lhc.my.id is active and associated with the brand_impersonation threat category. The observed page title matches the impersonated brand, DANA, indicating an attempt to imitate a legitimate online service. No drainer kit information is available from the supplied intelligence. The combination of impersonation indicators, active status, and infrastructure characteristics supports an elevated risk assessment for credential theft or fraudulent transaction workflows.
Technical indicators identify a VirusTotal detection score of 20/95 security vendors. The domain is registered through Cloudflare, Inc. and resolves to IP address 172.67.213.143, located in the US within AS13335 Cloudflare, Inc. No creation date is available from the provided intelligence. The domain has no SSL certificate, appears on 1 security blocklist, and has been blocked by PhishDestroy. These indicators collectively demonstrate externally observed malicious or suspicious behavior consistent with brand impersonation infrastructure.
The domain remains active at the time of assessment, leaving residual exposure for users who encounter links directing to this infrastructure. Recommended response actions include immediate blocking at network, DNS, email, and web gateway layers, continued monitoring for infrastructure changes, and preservation of relevant indicators for incident response and threat hunting. Any interaction with the site should be considered potentially unsafe until independent verification confirms otherwise. The absence of an SSL certificate does not reduce the operational risk, while the existing detection coverage and blocklist presence reinforce the elevated likelihood of malicious use.
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога