pub-ad3d40c665754dd4ab89a028b6551b6b[.]r2[.]dev
“Situs Game Online nthafoundation Toto Terbaik Dengan Layanan Digital Berkualitas”
pub-ad3d40c665754dd4ab89a028b6551b6b.r2.dev — 内容不可用. 品牌冒充:Manta. 证据摘要: VirusTotal 11/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); PhishDestroy score 83/100. 注册商: Cloudflare R2.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, pub-ad3d40c665754dd4ab89a028b6551b6b.r2.dev, is flagged as a high-risk credential theft operation targeting users through deceptive login interfaces. Analysis indicates the site is designed to harvest usernames, passwords, and other authentication credentials, likely for subsequent unauthorized access to accounts or financial exploitation. The threat type is specifically credential theft, not generic phishing, with infrastructure tailored to mimic legitimate authentication portals. Infrastructure analysis reveals the domain resolves to the IP address 104.18.50.34, a Cloudflare proxy endpoint commonly used to obfuscate malicious origins. VirusTotal detection data shows 6 out of 95 security vendors have flagged this domain as malicious, a notable indicator given the conservative nature of vendor detection thresholds. The domain is registered under Cloudflare’s R2 storage service, which provides anonymized hosting with minimal registration transparency. No historical creation date or registrar details are publicly available, further complicating attribution. Blocklist monitoring services have not yet widely adopted this domain, but the existing detections and proxy infrastructure align with known credential theft campaigns. Mitigation steps for users and organizations include immediate blocking of the domain and its resolving IP at the network perimeter. Endpoint protection systems should be updated to flag or quarantine any connections to pub-ad3d40c665754dd4ab89a028b6551b6b.r2.dev. Users who may have interacted with the domain should reset credentials for any accounts accessed during the exposure window, prioritizing financial, email, and administrative accounts. Multi-factor authentication (MFA) should be enforced where available to mitigate the impact of stolen credentials. Security teams are advised to monitor for anomalous authentication attempts, particularly from the IP 104.18.50.34, and review logs for any prior connections to this domain.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。