claeimddp-dgetrf[.]pays[.]web[.]id
“DANA - Apa pun transaksinya selalu ada DANA”
claeimddp-dgetrf.pays.web.id — 内容不可用. 品牌冒充:DANA; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 20/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Cluster25); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. 注册商: PT Registrasi Neva Ang….
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This site, claeimddp-dgetrf.pays.web.id, impersonates the brand DANA, as indicated by its page title "DANA - Apa pun transaksinya selalu ada DANA" and classification as a DANA impersonation scam. The threat posed is brand impersonation, likely used to deceive users into providing credentials or financial information under the pretense of a legitimate DANA service.
Technical evidence shows the site was flagged by 20 out of 95 VirusTotal vendors, with detection by ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, and Cluster25. It was created on 2026-02-21 and registered through PT Registrasi Neva Angkasa. The IP address is 148.113.46.149, located in India and hosted by AS16276 OVH SAS. The site has no SSL certificate and uses nameservers alaric.ns.cloudflare.com and cruz.ns.cloudflare.com. GridinSoft trust rating is 0 out of 100.
The site is currently offline. Based on the high detection rate, lack of SSL, and zero trust rating, the risk level is high. Users should not interact with this domain if it becomes active again.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
PD-20260118-CCE81B Recipient: abuse@ovhcloud.in 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。