dnizinbanksii[.]duckdns[.]org
“dnizinbanksii.duckdns.org”
dnizinbanksii.duckdns.org — المحتوى غير متوفر. نوع الاحتيال: Banking Phishing. ملخص الأدلة: VirusTotal 16/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: Gandi SAS.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of dnizinbanksii.duckdns.org indicates that the domain is being used for a banking phishing campaign. The page title returned by the host is identical to the domain name, providing no further contextual clues. The domain was registered on 12 April 2013 through Gandi SAS and is delegated to the DuckDNS dynamic DNS service using the three standard DuckDNS nameservers (ns1.duckdns.org, ns2.duckdns.org, ns3.duckdns.org). DNS resolution points to the IPv4 address 196.251.72.165, which is associated with a host located in South Carolina and listed as belonging to the entity “4445 Corporation”. The IP address currently appears on a single security blocklist and has been flagged by the PhishDestroy service as malicious.
VirusTotal has recorded detections from 16 of 93 security vendors for this domain, confirming a consensus among multiple scanning engines that the site hosts malicious content. The domain is also present on at least one public blocklist, reinforcing its classification as a threat. The limited blocklist presence suggests that detection is primarily driven by vendor scans rather than widespread abuse reports. No SSL/TLS information is available, and the site is presently offline, limiting real‑time verification of HTTP response codes or content. The lack of a live HTTP response means that Safe Browsing status cannot be verified at this time, and the absence of certificate data precludes assessment of trust scores.
The domain age of more than thirteen years may aid in evading some reputation‑based filters that prioritize newly created sites. Given the available evidence, defenders should continue to block traffic to both the domain and its resolved IP address at network perimeter devices. Updating URL filtering and DNS sinkhole configurations to include dnizinbanksii.duckdns.org and 196.251.72.165 will help prevent credential harvesting attempts.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | dnizinbanksii.duckdns.org |
malicious | Sinkholed |
| DNS0 Zero | dnizinbanksii.duckdns.org |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | dnizinbanksii.duckdns.org |
malicious | Sinkholed |
| Quad9 DNS | dnizinbanksii.duckdns.org |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب