MALICIOUS — CRITICAL
dash[.]clash[.]id
This domain, dash.clash.id, is flagged as a high-risk generic phishing threat as of July 12, 2026, and remains active.
- VirusTotal
- 5/91
- Blocklists
- No stored match
- sẵn có
- Hoạt động được biết đến lần cuối · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is network-abuse@google.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
dash.clash.id — Hoạt động được biết đến lần cuối (HTTP 200). Loại lừa đảo: Generic Phishing. Tóm tắt bằng chứng: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 80/100. Nhà đăng ký: PT Dewabisnis Digital ….
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
Evidence Analysis
This domain, dash.clash.id, is flagged as a high-risk generic phishing threat as of July 12, 2026, and remains active. The domain was registered on April 27, 2026, through PT Dewabisnis Digital Indonesia, a relatively recent registration that aligns with its malicious use. It resolves to IP address 142.251.127.121, located in the United States and hosted by Google LLC, with nameservers alexandra.ns.cloudflare.com and emerson.ns.cloudflare.com. The SSL certificate is issued by Google Trust Services under the WR3 hierarchy, and the page title is "Dashboard - Clash ID," indicating a possible impersonation of a service or platform named Clash ID, though the exact brand targeted is not confirmed beyond this title. Technology analysis reveals the use of Blogger, Java, Python, Firebase, OpenGSE, SweetAlert2, and jsDelivr, suggesting a complex stack that may include client-side scripting and backend infrastructure. The domain appears on one security blocklist and is blocked by PhishDestroy, with a Gridinsoft trust score of 0 out of 100, reflecting strong negative reputation signals. VirusTotal data shows 3 out of 91 security vendors flagging this domain, indicating partial detection across the security community. The HTTP status code is 200, confirming the site is live and serving content. Defenders should treat this domain as an active phishing threat, monitor for any changes in IP or nameserver records, and block access at the network level. The exact phishing payload or landing page content has not been analyzed, so caution is warranted when interacting with the domain. Given the low detection rate and recent registration, this domain may still be in early stages of a campaign, and organizations should update threat intelligence feeds accordingly.
Phạm vi dữ liệu12 recorded checks
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Công nghệ · 7 identified
Blogger is a blog-publishing service that allows multi-user blogs with time-stamped entries.
www.blogger.com Độ tin cậy 100%Java is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com Độ tin cậy 100%Firebase is a Google-backed application development software that enables developers to develop iOS, Android and Web apps.
firebase.google.com Độ tin cậy 100%OpenGSE is a test suite used for testing servlet compliance. It is deployed by using WAR files that are deployed on the server engine.
code.google.com Độ tin cậy 100%SweetAlert2 is a JavaScript library that provides customisable, visually appealing, and responsive alert and modal dialog boxes for web applications.
sweetalert2.github.io Độ tin cậy 100%JSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com Độ tin cậy 100%Phân tích của VirusTotal
Phân tích hiệu suất trang
Google PageSpeed Insights — mobile performance audit of dash.clash.id · checked Apr 27, 2026
Phân tích cấu hình trang
Bằng chứng và các báo cáo bên ngoàiIndependent lookups and source reports
PD-20260427-18155B Recipient: network-abuse@google.com Victim safety and official reportingImmediate actions and verified reporting channels
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.