kurir[.]pengiriman[.]eventpromo[.]my[.]id
“Account Suspended”
kurir.pengiriman.eventpromo.my.id — 内容不可用. 诈骗类型:Account Takeover. 证据摘要: VirusTotal 17/93 (Criminal IP, BitDefender, CRDF, CyRadar, ESET); PhishDestroy score 95/100. 注册商: PT Cloud Hosting Indon….
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain kurir.pengiriman.eventpromo.my.id has been identified as a generic phishing site designed to impersonate legitimate courier or logistics services. Analysis indicates this infrastructure was actively used to deceive users into submitting sensitive information, likely through fake login portals or fraudulent delivery notifications. The domain is currently marked as taken down, though prior activity suggests it was operational for malicious purposes. Infrastructure analysis reveals the domain was registered on January 13, 2025, through PT Cloud Hosting Indonesia. It resolves to the IP address 62.84.180.140, hosted on AS51167 (Contabo GmbH) in France. Security vendors on VirusTotal flagged this domain as malicious, with 17 out of 95 engines detecting it as a threat. The domain appears on one security blocklist, and its page title, 'Account Suspended,' suggests an attempt to mimic a legitimate service disruption notice. Notably, the domain lacks an SSL certificate, a common red flag for fraudulent sites. The risk level for this domain is classified as elevated due to its active use in phishing campaigns and the absence of basic security measures. While the domain is currently inactive, organizations and users should remain vigilant for similar impersonation attempts. Recommended actions include blocking the domain and IP address in network security controls, monitoring for related subdomains or newly registered lookalike domains, and educating users on recognizing phishing indicators such as missing SSL certificates and suspicious registrar details. Historical DNS records and WHOIS data should be preserved for further investigation if required.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。