pub-321ad47684174ff88663e8553aab91d7[.]r2[.]dev
“DANATOTO : Platform Permainan Slot Online Gacor Terkemuka & Slot Qris 5000 Gampang Menang”
pub-321ad47684174ff88663e8553aab91d7.r2.dev — 内容不可用. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 1/91 (alphaMountain.ai); PhishDestroy score 55/100. 注册商: Cloudflare R2.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain is flagged as a confirmed generic phishing site hosting malicious content designed to deceive users. The infrastructure leverages Cloudflare R2 storage, a legitimate cloud service, to distribute phishing payloads while obscuring the true origin through a subdomain-based delivery mechanism. The site remains active with no detections recorded across 95 VirusTotal engines, suggesting evasion of current signature-based defenses. Analysis indicates this domain resolves to IP address 104.18.54.45, which is associated with Cloudflare’s edge network. The domain was registered via Cloudflare R2, a storage service, and shows no recorded detections on VirusTotal as per the latest scan. The IP address has not been identified on any known blocklists or threat intelligence feeds at this time, and no historical reputation scores are available. The lack of detection suggests a low-profile operation still in active deployment phase. Mitigation requires immediate action from network defenders. Organizations should block the domain at DNS and firewall levels using the exact string pub-321ad47684174ff88663e8553aab91d7.r2.dev and the associated IP 104.18.54.45. Users interacting with this domain should be warned of potential credential theft risks. Further investigation is required to identify the specific lure content and lures used in this campaign. This domain should be treated as an active threat vector pending additional intelligence or remediation.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。