The official Indonesian school domain .sch.id at https://sukasari5tng.sch.id/ is being abused for ph ...
show moreThe official Indonesian school domain .sch.id at https://sukasari5tng.sch.id/ is being abused for phishing and illegal online gambling promotion. The phishing URL detected is https://sukasari5tng.sch.id/?sukasari_id=dax69. Please take immediate action to investigate and block this IP to prevent further harm to internet users.
show less
I have reviewed the URL you provided: https://bkpsdm.burselkab.go.id/?news_ID=dax69. Currently, the ...
show moreI have reviewed the URL you provided: https://bkpsdm.burselkab.go.id/?news_ID=dax69. Currently, the page appears to be inaccessible or does not display any content. This could be due to the page being removed, renamed, or restricted.
If you have specific concerns about this URL or need assistance with a particular issue related to it, please provide more details so I can offer more targeted help.
show less
This IP is being used to host or serve content that is part of a phishing and redirection scam invol ...
show moreThis IP is being used to host or serve content that is part of a phishing and redirection scam involving domain impersonation. The phishing URLs involved include:
- https://sdn62bandaaceh.sch.id/?commont=DAX69
- https://gasmuncak.pages.dev/?commont=DAX69
The domain sdn62bandaaceh.sch.id is a legitimate educational institution in Indonesia and is being misused to redirect traffic to illegal gambling/slot sites under the brand "DAX69". This campaign appears to use AMP-style redirects hosted via pages.dev infrastructure.
This poses a serious threat to users and should be investigated or blocked immediately.
show less
The official academic domain https://lpm.iainkendari.ac.id/ is being abused and used for phishing. T ...
show moreThe official academic domain https://lpm.iainkendari.ac.id/ is being abused and used for phishing. The following URL:
https://lpm.iainkendari.ac.id/wp-content/?or_id=dax69
redirects or promotes a suspicious and illegal website.
Additionally, there's an AMP version hosted at:
https://lpmiainkendari.pages.dev/?or_id=DAX69
This is a serious abuse of a government-backed educational domain (.ac.id) which misleads Indonesian users and may lead to data theft or fraud. Please investigate and take action accordingly.
show less
This domain is being used as a redirect from a legitimate academic Indonesian domain (.ac.id) to wha ...
show moreThis domain is being used as a redirect from a legitimate academic Indonesian domain (.ac.id) to what appears to be a phishing or illegal gambling site. It is misleading users and potentially stealing credentials. AMP redirect example: https://talitakumacid.pages.dev/?website=BRI4D
show less
This IP is hosting or associated with a phishing page abusing an official Indonesian government doma ...
show moreThis IP is hosting or associated with a phishing page abusing an official Indonesian government domain (.go.id). The attacker uses the trusted domain to lure users into clicking malicious redirect links.
Example of the phishing URL:
https://anjab.riau.go.id/inhu/?profile=judolbet88
Redirects to: https://0situs969.pages.dev/ams/JUDOLBET88
This is a serious case of government domain abuse that could lead to identity theft or fraud. Please investigate and take action to prevent further misuse.
show less
This IP address is hosting phishing URLs designed to steal user information. The URLs involved are:
...
show moreThis IP address is hosting phishing URLs designed to steal user information. The URLs involved are:
https://disposisi.umk.ac.id/POL88
https://disposisi-umk.pages.dev/?page=POL88
Please investigate and block this IP to prevent further abuse.
show less
This IP address (194.163.42.30) is involved in phishing activities by hosting or redirecting to dece ...
show moreThis IP address (194.163.42.30) is involved in phishing activities by hosting or redirecting to deceptive URLs that impersonate government or institutional domains. It was observed redirecting users to fake pages mimicking official websites, potentially stealing user credentials or leading to malicious content. This poses a serious risk to public safety, user data, and trust in legitimate online services. Please investigate and take appropriate action to mitigate further abuse.
show less
This IP address (152.118.24.138) is being used to host or redirect to a phishing page impersonating ...
show moreThis IP address (152.118.24.138) is being used to host or redirect to a phishing page impersonating a government or official organization. The phishing URL is:
https://eproc.jasatirta2.co.id/vendor/mews/?permisi=POL88
This page eventually redirects to an external AMP link containing scam/gambling content:
https://daftarjasatirta2.pages.dev/?permisi=pol88
The domain appears legitimate (using .co.id), but the content is malicious and misleading. Users are at risk of credential theft and being lured into fraudulent services. This IP should be investigated and blacklisted to prevent further harm.
show less
This IP address (68.65.122.187) is being used as a redirect destination in a phishing campaign. It i ...
show moreThis IP address (68.65.122.187) is being used as a redirect destination in a phishing campaign. It is connected to a suspicious URL that impersonates legitimate websites to lure users into interacting with fake login pages or gambling-related content. The redirection is typically triggered via compromised government or educational domains (e.g., *.go.id or *.ac.id). This is a serious security risk and should be investigated and mitigated immediately.
show less
This IP address (103.180.162.186) is being used as part of a phishing campaign involving malicious r ...
show moreThis IP address (103.180.162.186) is being used as part of a phishing campaign involving malicious redirects and suspicious subdomains. It was found redirecting users to gambling-related phishing websites via compromised or spoofed URLs, particularly those impersonating government or educational domains.
The associated phishing URLs led to AMP pages hosting fake login interfaces and suspicious redirects, putting users at risk of credential theft and fraud.
Immediate investigation and blacklisting of this IP is highly recommended to prevent further abuse and protect end users.
show less
This IP address (104.21.13.31) is associated with a phishing operation. The malicious URL hosted on ...
show moreThis IP address (104.21.13.31) is associated with a phishing operation. The malicious URL hosted on this IP was observed redirecting users from a seemingly legitimate domain (e.g., .go.id or .co.id subdomain) to a third-party website that imitates trusted services and encourages users to engage with fraudulent or gambling content.
This poses a high security risk as it leverages reputable domains to deceive users and steal sensitive information. Immediate investigation and mitigation are recommended to prevent further harm.
show less
This IP address (172.67.132.124) is being used as part of a phishing and redirection scheme. It host ...
show moreThis IP address (172.67.132.124) is being used as part of a phishing and redirection scheme. It hosts or serves content that impersonates trusted domains or services and redirects users to external phishing pages promoting illegal online gambling platforms.
The phishing structure includes the use of trusted .go.id or .co.id subdomains as decoys, which then redirect traffic via AMP links associated with this IP. This tactic is designed to deceive users and exploit the credibility of government or institutional websites.
This behavior is malicious and should be considered a high-risk phishing vector. Please investigate and take appropriate action to mitigate any further abuse originating from this IP.
show less
This IP address (36.64.61.158) was found serving a phishing page impersonating a government-affiliat ...
show moreThis IP address (36.64.61.158) was found serving a phishing page impersonating a government-affiliated .co.id domain, specifically via the URL:
https://eproc.jasatirta2.co.id/vendor/mews/?permisi=POL88
The page contains redirect scripts that forward users to an external AMP-based URL:
https://daftarjasatirta2.pages.dev/?permisi=pol88
The target page promotes illegal gambling and fraudulent content. The redirection is automatic and disguised behind what appears to be a legitimate government procurement portal. This strongly indicates abuse of the IP for hosting phishing infrastructure or facilitating redirection for malicious intent.
Please investigate and take appropriate action against this IP.
show less
This IP address (103.134.152.17) has been involved in phishing activities by hosting or redirecting ...
show moreThis IP address (103.134.152.17) has been involved in phishing activities by hosting or redirecting to malicious URLs impersonating legitimate Indonesian government or institutional domains (e.g., .go.id, .co.id, .ac.id). The phishing links are designed to trick users into clicking fake login or redirect pages related to online gambling or scams. Immediate investigation and blacklisting are recommended to prevent data theft and reputational damage.
show less
This IP address (152.118.24.138) is associated with a phishing page hosted under the domain https:// ...
show moreThis IP address (152.118.24.138) is associated with a phishing page hosted under the domain https://eproc.jasatirta2.co.id/vendor/mews/?permisi=POL88. The site appears to be impersonating an official government or enterprise portal to trick users into clicking malicious links that redirect to unauthorized gambling or scam content.
It poses a significant threat by abusing a legitimate .co.id domain, misusing government trust, and potentially collecting sensitive user data. Immediate investigation and mitigation are strongly advised to prevent further phishing attacks from this IP.
show less
This IP address (103.152.5.92) is being used to host or redirect users to phishing content related t ...
show moreThis IP address (103.152.5.92) is being used to host or redirect users to phishing content related to fake gambling or scam pages. It was observed redirecting from legitimate-looking domains (e.g., *.co.id or *.ac.id) to malicious AMP pages containing fraudulent schemes.
The URL involved:
- https://eproc.jasatirta2.co.id/vendor/mews/?permisi=POL88
- Redirecting to: https://daftarjasatirta2.pages.dev/?permisi=pol88
The redirection ultimately points to an IP associated with this suspicious activity.
This behavior violates user safety and promotes fraudulent or deceptive online activity. Please investigate and take appropriate action against this IP.
show less
This IP address (194.163.42.30) is associated with phishing activities. It is used to host or redire ...
show moreThis IP address (194.163.42.30) is associated with phishing activities. It is used to host or redirect to fake websites that impersonate official Indonesian government or institutional domains (e.g., .go.id, .ac.id, .co.id). These phishing pages often redirect to external AMP or gambling scam links that attempt to deceive users and potentially steal sensitive information. Immediate investigation and mitigation are highly recommended to protect public trust and prevent further harm.
show less
This IP address (152.118.24.138) is being used to host or serve phishing content. It is associated w ...
show moreThis IP address (152.118.24.138) is being used to host or serve phishing content. It is associated with a malicious page at https://eproc.jasatirta2.co.id/vendor/mews/?permisi=POL88 which redirects users to an external gambling/scam AMP site (https://daftarjasatirta2.pages.dev/?permisi=pol88). This activity misleads users by impersonating official government-related services and poses a serious threat of data theft and fraud. Immediate action is recommended to prevent further abuse.
show less
Situs tersebut menampilkan tampilan halaman login Gmail yang sangat mirip aslinya. Setelah pengguna ...
show moreSitus tersebut menampilkan tampilan halaman login Gmail yang sangat mirip aslinya. Setelah pengguna memasukkan alamat email dan kata sandi, form akan mengirim data kredensial ke server penyerang.
show less
DNS CompromisePhishingBlog SpamHackingSQL InjectionIoT Targeted
Situs tersebut menampilkan tampilan halaman login Gmail yang sangat mirip aslinya. Setelah pengguna ...
show moreSitus tersebut menampilkan tampilan halaman login Gmail yang sangat mirip aslinya. Setelah pengguna memasukkan alamat email dan kata sandi, form akan mengirim data kredensial ke server penyerang.
show less
DNS CompromiseDNS PoisoningFraud OrdersPhishingVPN IPHackingSQL InjectionWeb App Attack
Situs tersebut menampilkan tampilan halaman login Gmail yang sangat mirip aslinya. Setelah pengguna ...
show moreSitus tersebut menampilkan tampilan halaman login Gmail yang sangat mirip aslinya. Setelah pengguna memasukkan alamat email dan kata sandi, form akan mengirim data kredensial ke server penyerang.
show less
DNS CompromiseFraud OrdersDDoS AttackPhishingEmail Spam
The IP address is hosting a phishing website under the .ac.id domain, which is typically used by edu ...
show moreThe IP address is hosting a phishing website under the .ac.id domain, which is typically used by educational institutions. The website is attempting to steal sensitive information by impersonating a legitimate platform. This site contains suspicious behavior and may be redirecting users to fraudulent or malicious pages.
show less
This IP is hosting a phishing page under an Indonesian academic domain (.ac.id), which increases the ...
show moreThis IP is hosting a phishing page under an Indonesian academic domain (.ac.id), which increases the risk of user trust and deception. The URL is:
https://jab.hangtuah.ac.id/public/?gacor=pol88
The page appears to redirect to fraudulent gambling content and may be collecting sensitive user data. Immediate investigation and blacklisting are recommended.
show less
This IP address is associated with a phishing website that attempts to deceive users by impersonatin ...
show moreThis IP address is associated with a phishing website that attempts to deceive users by impersonating a legitimate domain. The phishing page is hosted under an Indonesian educational domain (.sch.id) and appears to redirect users to fraudulent or gambling-related content.
Evidence URL:
https://abt.smandung.sch.id/home/?meta=pol88
Suggested Action:
Please investigate and flag this IP address for phishing. Immediate blacklisting or notification to the hosting provider is recommended to prevent further harm.
show less
PhishingBlog SpamWeb App Attack
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.