pemblokiran-shoppe[.]annyoying[.]my[.]id
“Pencetakan Kupon BRImo”
pemblokiran-shoppe.annyoying.my.id — Контент недоступний. Уособлення бренду: ["whatsapp"]; Тип шахрайства: Banking Phishing. Зведення доказів: VirusTotal 21/94 (ADMINUSLabs, Cluster25, CRDF, CyRadar, DNS8); CF Radar malicious; PhishDestroy score 95/100. Реєстратор: PT JC Indonesia.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of pemblokiran-shoppe.annyoying.my.id shows a domain actively used for banking phishing, as indicated by the reported scam type. The domain resolves to 172.67.156.163, an address owned by Cloudflare, Inc. in Canada, and is served through Cloudflare’s infrastructure, with HTTP/3 support observed. The SSL certificate is issued by Google Trust Services under the WE1 certificate authority, confirming the use of a valid TLS certificate despite malicious intent. VirusTotal records indicate that 21 of 94 scanned security vendors flagged the domain, demonstrating a moderate detection consensus.
Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on a single security blocklist. Registration data lists PT JC Indonesia as the registrar, and the authoritative nameservers are henry.ns.cloudflare.com and ursula.ns.cloudflare.com. The page title retrieved from the site is "Pencetakan Kupon BRImo", suggesting an attempt to lure victims with a coupon‑related lure tied to the BRImo banking service. The domain has been taken offline as of the report date, and PhishDestroy has already added it to its blocklist.
Because the site is currently inactive, direct content analysis is limited; the exact page layout, credential‑capture mechanisms, and any additional payloads remain unverified. Defenders should continue to block the domain and its associated IP address at network perimeter devices, update DNS‑based blocklists, and monitor for any rapid re‑registration or similar naming patterns. Additional surveillance of Cloudflare‑hosted assets linked to the same nameservers may reveal related infrastructure. Organizations should educate users about unsolicited coupon offers linked to BRImo and enforce multi‑factor authentication for banking services to mitigate potential credential compromise.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога