xn[.]wttef[.]my[.]id
xn.wttef.my.id — Контент недоступний (HTTP 502). Уособлення бренду: Genericcloudflare. Зведення доказів: VirusTotal 14/95 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 92/100. Реєстратор: PT Cloud Hosting Indon….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis indicates that the domain xn.wttef.my.id, registered on February 21, 2026, through PT Cloud Hosting Indonesia, exhibits characteristics consistent with credential phishing infrastructure. The domain resolves to the IP address 172.67.168.60, which is geolocated in the United States and associated with AS13335 (Cloudflare, Inc.). This IP falls within Cloudflare’s network, a common hosting choice for both legitimate and malicious actors due to its proxy services and privacy features. The domain’s nameservers, EXPIRED1.CLOUDHOST.ID and EXPIRED2.CLOUDHOST.ID, suggest an expired or repurposed hosting configuration, which may indicate an attempt to evade detection or reuse compromised infrastructure. As of the report date, the domain has been flagged by 14 of 95 security vendors on VirusTotal, a detection rate that aligns with known phishing campaigns.
Additionally, the domain appears on at least one security blocklist and has been blocked by PhishDestroy, further corroborating its malicious classification. The Gridinsoft trust score of 0/100 reinforces the assessment of elevated risk. The SSL certificate, issued by WE1, does not provide additional indicators of compromise but is consistent with low-effort phishing domains that rely on basic encryption to appear legitimate. No specific brand impersonation or phishing kit details are available from the provided data, and the exact content of the phishing page remains unanalyzed.
However, the domain’s structure and detection profile suggest it was likely used for harvesting credentials or distributing malicious payloads. Defenders are advised to treat this domain as compromised and include it in blocklists for web gateways, email filters, and endpoint protection systems. Network administrators should monitor for connections to 172.67.168.60 and the associated Cloudflare ASN, particularly in environments where credential theft poses a high risk.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога