الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 11. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

trojwesternonline[.]com[.]horizonnationalbk[.]com

“Trojan Western International Bank”

حكم التهديد حرجة 87/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
VirusTotal detections: 11 (vendor total unavailable) Spamhaus DBL: DBL_SPAM URLQuery threat systems: 1 alert انتحال العلامة التجارية: Facebook
11/03/2026 Facebook 1 Report Sent
ملخص التقرير

trojwesternonline.com.horizonnationalbk.com — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Facebook; نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 11 detections (engine total unavailable) (ADMINUSLabs, BitDefender, CRDF, CyRadar, Fortinet); URLQuery 1 alert; Spamhaus DBL_SPAM; PhishDestroy score 87/100. مسجّل النطاق: NameSilo.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
9BBACF1F
الدرجة
87/100

Analysis of trojwesternonline.com.horizonnationalbk.com performed on July 25, 2026 indicates the domain is associated with a generic phishing campaign targeting users of Western International Bank. The page title returned by the host is "Trojan Western International Bank", confirming the intended victim brand. The domain was registered on March 11, 2026 through NameSilo, LLC and is hosted on an IP address 79.133.41.250 that resolves to an Ultahost, Inc. network in Germany (AS214036). Nameserver records point to ns1.ultahost.com and ns3.ultahost.com, consistent with the hosting provider. TLS is provided by a Let’s Encrypt R12 certificate, which validates the domain but does not imply legitimacy.

The site employed a stack that included YouTube embeds, Bootstrap framework, LiteSpeed server, OWL Carousel, jQuery, Popper, and HTTP/3 support, suggesting a fairly modern web stack. The domain appears on the PhishDestroy blocklist and has been flagged by 11 of 95 VirusTotal scanners, reinforcing the malicious classification. It is currently taken offline, which may be the result of takedown actions or hosting changes. No additional public blocklists beyond the single entry were observed, and safe‑browsing signals were not disclosed.

Uncertainty remains regarding the exact content served before the takedown, the presence of credential‑collection forms, and any downstream command‑and‑control infrastructure. Defenders should continue to block the domain at network perimeter, monitor DNS queries for the associated IP and nameservers, and add the domain to internal indicator lists. Because the SSL certificate is publicly trusted, users may be deceived by the lock icon; user education should stress that a valid HTTPS certificate does not guarantee authenticity. Ongoing observation of the registrar and IP range is advised in case the threat actor re‑hosts the phishing site on adjacent infrastructure.

VirusTotal
VirusTotal
11 det.
URLQuery
URLQuery
1 threat alert
شهادة TLS
Let's Encrypt
العمر
5 mo
الحالة المرصودة
المحتوى غير متوفر 502
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات VirusTotal 11 detections · vendor total unavailable URLQuery 1 threat-system alert PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 14 تم الفحص — لا يوجد حظر TLS valid certificate, 55d WHOIS 5 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات Registrar context
Registrar context NameSilo
Stored registration data identifies NameSilo as the registrar. PhishDestroy maintains separate registrar investigations; that broader material is contextual and is not an independent detection for this domain.
Review source investigation
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU trojwesternonline.com.horizonnationalbk.com malicious Sinkholed

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
15/15
Sent Report Recorded
Stored sent-report record for registrar NameSilo, LLC, hosting provider, 3 abuse contacts
abuse@first-colo.netabuse@namesilo.comu-abuse@ultahost.com
11/03/2026

حالة قوائم الحظر العامة

لقطة محفوظة

عنوان الصفحة
Trojan Western International Bank
Impersonates
Facebook Gmail Instagram LinkedIn Mastercard Visa
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 55 days

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN LiteSpeed · AS214036 Ultahost, Inc.
سمعة عنوان IP abuse score 0/100 1 report checked 14/07/2026
Registrar (base domain) NameSilo US(US) PhishDestroy Investigation
جهة الإبلاغ عن إساءة الاستخدامabuse@first-colo.net, abuse@namesilo.com, u-abuse@ultahost.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ horizonnationalbk.com →
عنوان IP 79.133.41.250 DE
الموقع الجغرافيDE Mörfelden-Walldorf, DE
الشبكةAS214036 · Ultahost, Inc.
Registration (base domain)horizonnationalbk.com · تم إنشاؤه 11/03/2026 (162d)
حالة HTTP502 Error
الوقت حتى أول تعذّر للوصول 4 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف11/03/2026
DOM Analysisanalyzed 29/07/2026score 73/1006 brand signals
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://trojwesternonline.com.horizonnationalbk.com/
خوادم الأسماءns3.ultahost.com
TLS Fingerprint
TLS Observationvalid from 04/02/2026scanned 15/03/2026
TLS SAN Domainsautodiscover.horizonnationalbk.comautodiscover.trojwesternonline.comcpanel.horizonnationalbk.comcpanel.trojwesternonline.comcpcalendars.horizonnationalbk.comcpcalendars.trojwesternonline.comcpcontacts.horizonnationalbk.comcpcontacts.trojwesternonline.comctruncs.com.horizonnationalbk.comhorizonnationalbk.commail.horizonnationalbk.commail.trojwesternonline.comtrojwesternonline.comumfibkonline.horizonnationalbk.comwebdisk.horizonnationalbk.com+8
Case ID
ICANN OVERSIGHT Registration: horizonnationalbk.com

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain horizonnationalbk.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
التقنيات · 7 identified
YouTube
Bootstrap
UI frameworks

Popular CSS framework for responsive, mobile-first web development.

LiteSpeed
Web servers

High-performance web server compatible with Apache configurations.

OWL Carousel
JavaScript libraries

Touch-enabled jQuery plugin for responsive carousel sliders.

jQuery
JavaScript libraries

Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.

Popper
HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

11 detections recorded · vendor total unavailable
View on VT
Last analyzed
ADMINUSLabs
BitDefender
CRDF
CyRadar
Fortinet
G-Data
كاسبرسكي
Lionic
SOCRadar
سوفوس
Webroot
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of trojwesternonline.com.horizonnationalbk.com · checked Mar 11, 2026

51
Needs Work
Performance
FCP
1.8s
First Contentful Paint
LCP
8.48s
Largest Contentful Paint
CLS
0.409
Cumulative Layout Shift
TBT
26ms
Total Blocking Time
SI
5.26s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

الأدلة والتقارير الخارجية

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260311-5A9CAD Recipient: abuse@first-colo.net
Page title stored with report: Trojan Western International Bank
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 288.8 KB
نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/trojwesternonline.com.horizonnationalbk.com"
  title="PhishDestroy threat report for trojwesternonline.com.horizonnationalbk.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.