brndnsia[.]com
Перевірка домену brndnsia.com на фішинг і безпеку
“𝙆𝙪𝙥𝙤𝙣 𝙐𝙣𝙙𝙞𝙖𝙣 | 𝘽𝙖𝙣𝙠 𝘽𝙍𝙄 𝟮𝟬𝟮𝟱”
brndnsia.com — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 18 detections (engine total unavailable) (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, Cluster25, CRDF); URLQuery 7 alerts; Google Safe Browsing flagged; PhishDestroy score 95/100. Реєстратор: CV. Rumahweb Indonesia.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, brndnsia.com, is identified as a high-risk credential theft operation specifically targeting customers of Bank BRI, an Indonesian financial institution. The site presents itself as a legitimate Bank BRI 2025 promotional platform offering coupons or undian (lottery), a common social engineering tactic to lure victims into entering sensitive banking credentials, personal identification details, or one-time passwords (OTPs). Analysis indicates the domain is designed to harvest login credentials, which could lead to unauthorized account access, financial fraud, or identity theft. The use of Bank BRI branding, including its logo and promotional language, increases the likelihood of successful deception among Indonesian users familiar with the bank’s legitimate campaigns. Infrastructure analysis reveals multiple technical indicators supporting the malicious classification of brndnsia.com. The domain was registered on February 21, 2026, through CV. Rumahweb Indonesia, a registrar frequently associated with recently established phishing domains. It resolves to the IP address 103.30.147.20, hosted under AS46050 (PT JC Indonesia), an autonomous system previously linked to other fraudulent activities. The domain lacks an SSL certificate, a red flag for users accustomed to secure banking sites. Detection metrics further confirm its malicious nature: VirusTotal reports 18 out of 95 security vendors flagging the domain as malicious, while Google Safe Browsing explicitly classifies it as phishing. Additionally, the domain appears on one security blocklist and is actively blocked by at least one anti-phishing service, reinforcing its high-risk status. Users who have visited brndnsia.com or interacted with its content should take immediate remedial actions to mitigate potential risks. First, any credentials entered on the site must be considered compromised and should be changed immediately across all platforms where the same or similar passwords were used. Affected individuals should contact Bank BRI through official channels to report the incident and monitor their accounts for unauthorized transactions. Enabling multi-factor authentication (MFA) on all financial and sensitive accounts is strongly recommended to prevent further unauthorized access. Users are also advised to scan their devices for malware, as phishing sites may deploy additional payloads or redirect to malicious downloads. Finally, reporting the domain to local cybersecurity authorities or consumer protection agencies can aid in broader mitigation efforts and prevent further victimization.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | brndnsia.com |
malicious | Sinkholed |
| Quad9 DNS | brndnsia.com |
malicious | Sinkholed |
| Cloudflare DNS | brndnsia.com |
malicious | Sinkholed |
| Hagezi Threat Feed | brndnsia.com |
malicious | Sinkholed |
| OpenDNS | brndnsia.com |
phishing | Phishing Block |
| DNS4EU | ibanking-bankjateng.whf.bz |
malicious | Sinkholed |
| OpenDNS | ibanking-bankjateng.whf.bz |
phishing | Phishing Block |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260131-47F04A Recipient: abuse@rumahweb.co.id Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога