incentrbfcustagingnet[.]azurewebsites[.]net
“Login - RBFCU STAR”
incentrbfcustagingnet.azurewebsites.net — 内容不可用. 品牌冒充:Rbfcu; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 16/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 1 alert; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. 注册商: Microsoft Azure.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain incentrbfcustagingnet.azurewebsites.net was registered on March 24, 2026 through Microsoft Azure and is hosted on a Microsoft Azure App Service instance in the southcentralus region (IP 40.74.255.112, United States). The site presented a login page titled "Login - RBFCU STAR" and was identified as a credential phishing operation targeting RBFCU customers. Infrastructure analysis shows the service runs on Windows Server with IIS, employs ASP.NET, and serves front‑end assets from Bootstrap, jQuery UI, jQuery CDN, Modernizr, and Cloudflare. The SSL certificate is issued by Microsoft Corporation under the Microsoft Azure RSA TLS Issuing CA 04 chain, confirming the use of Azure’s default certificate provisioning.
Security tooling indicates the domain appears on a single blocklist and has been flagged by 16 of 94 vendors on VirusTotal. Independent trust rating services assigned extremely low scores: Gridinsoft 0/100 and Scamadviser 1/100. PhishDestroy has explicitly blocked the domain. No nameserver records were returned, and the site has been taken offline at the time of this report.
Defenders should treat any traffic to this host as malicious. Immediate actions include blocking the IP address 40.74.255.112 at perimeter firewalls, updating DNS blocklists to include the fully qualified domain name, and surveilling outbound connections from internal hosts that may have attempted credential submission. Incident response teams should search for RBFCU credential exposure in logs, reset any compromised accounts, and advise affected users to change passwords. Continuous monitoring of Azure App Service IP ranges is recommended, as the attacker leveraged legitimate cloud infrastructure to lend credibility to the phishing page.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | incentrbfcustagingnet.azurewebsites.net |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
取证情报
所用技术 · 13 identified
Popular CSS framework for responsive, mobile-first web development.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comLegacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Icon font library.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of incentrbfcustagingnet.azurewebsites.net · checked Mar 24, 2026
证据与外部报告
PD-20260324-11076A Recipient: abuse@microsoft.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。