restrycreatdnnns[.]frbg[.]biz[.]id
restrycreatdnnns.frbg.biz.id — 未验证. 品牌冒充:Genericcloudflare; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 13/91 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; PhishDestroy score 89/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, restrycreatdnnns.frbg.biz.id, was identified as a credential theft phishing site designed to harvest login credentials, financial details, or other sensitive information from unsuspecting users. Such infrastructure typically mimics legitimate services, tricking users into entering credentials that are then captured by threat actors for fraud, account takeover, or further exploitation. The site may have presented itself as a trusted entity, such as a banking portal, email service, or corporate login page, to increase the likelihood of successful compromise. Analysis indicates the domain was created on February 21, 2026, and is hosted on infrastructure associated with Cloudflare, Inc. (AS13335) at IP address 188.114.97.3. Security vendors flagged the domain in 17 out of 95 scans on VirusTotal, and it appears on at least one security blocklist. The SSL certificate, issued under the identifier WE1, does not align with typical certificates used by legitimate services, further suggesting malicious intent. The domain has since been taken offline, but its infrastructure and registration details remain relevant for threat correlation. If you visited restrycreatdnnns.frbg.biz.id or entered any information on the site, immediate action is required. First, change passwords for any accounts that may have been exposed, prioritizing financial, email, and work-related credentials. Enable multi-factor authentication (MFA) where available to add an additional layer of security. Monitor accounts for unauthorized activity, such as unfamiliar transactions or login attempts, and report any suspicious behavior to the relevant service provider. If financial information was entered, contact your bank or card issuer to freeze accounts and prevent fraudulent transactions. Additionally, scan your device for malware using updated security tools to ensure no secondary infections were introduced.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。