pub-321ad47684174ff88663e8553aab91d7[.]r2[.]dev
“DANATOTO : Platform Permainan Slot Online Gacor Terkemuka & Slot Qris 5000 Gampang Menang”
pub-321ad47684174ff88663e8553aab91d7.r2.dev — Контент недоступний. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 1/91 (alphaMountain.ai); PhishDestroy score 55/100. Реєстратор: Cloudflare R2.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as a confirmed generic phishing site hosting malicious content designed to deceive users. The infrastructure leverages Cloudflare R2 storage, a legitimate cloud service, to distribute phishing payloads while obscuring the true origin through a subdomain-based delivery mechanism. The site remains active with no detections recorded across 95 VirusTotal engines, suggesting evasion of current signature-based defenses. Analysis indicates this domain resolves to IP address 104.18.54.45, which is associated with Cloudflare’s edge network. The domain was registered via Cloudflare R2, a storage service, and shows no recorded detections on VirusTotal as per the latest scan. The IP address has not been identified on any known blocklists or threat intelligence feeds at this time, and no historical reputation scores are available. The lack of detection suggests a low-profile operation still in active deployment phase. Mitigation requires immediate action from network defenders. Organizations should block the domain at DNS and firewall levels using the exact string pub-321ad47684174ff88663e8553aab91d7.r2.dev and the associated IP 104.18.54.45. Users interacting with this domain should be warned of potential credential theft risks. Further investigation is required to identify the specific lure content and lures used in this campaign. This domain should be treated as an active threat vector pending additional intelligence or remediation.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога