vh18414[.]vh[.]net[.]pl
“Konto utrzymywane na serwerach VH.PL”
vh18414.vh.net.pl — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Tdbank; نوع الاحتيال: Impersonation. ملخص الأدلة: VirusTotal 5/91 (Cluster25, CRDF, Fortinet, SOCRadar, Webroot); URLScan malicious verdict; PhishDestroy score 80/100. مسجّل النطاق: Prociv Sp. z o.o.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
vh18414.vh.net.pl is a subdomain of vh.net.pl. PhishDestroy first observed the hostname on Aug 16, 2026. Stored content metadata identifies Tdbank as the apparent target. The captured page title is “Konto utrzymywane na serwerach VH.PL”. Stored page analysis classifies the content as impersonation. Current evidence score: 80/100 (critical).
Positive findings are stored from 2 sources: VirusTotal and URLScan. VirusTotal recorded 5 detections among 91 engines: Cluster25, CRDF, Fortinet, SOCRadar, Webroot on Aug 16, 2026 at 23:33 UTC. URLScan returned a malicious verdict with score 100; scan metadata linked the capture to Tdbank and assigned phishing as its category on Aug 16, 2026 at 05:08 UTC. Non-positive and contextual checks: The separate external-blocklist snapshot contained no matches on Aug 16, 2026 at 22:20 UTC. URLQuery recorded no positive detection; no observation timestamp was retained. Google Safe Browsing returned no flag on Aug 16, 2026 at 21:33 UTC.
HTTP 200 was recorded on Aug 16, 2026 at 22:15 UTC. Registration records for the registrable domain vh.net.pl list Prociv Sp. z o.o. as the registrar and May 30, 2019 as the creation date. At collection time, the hostname resolved to 83.168.99.244. The recorded endpoint location is PL. The stored server header is LiteSpeed. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. TLS metadata lists Let's Encrypt as the certificate issuer with validity through Nov 10, 2026; checked Aug 16, 2026 at 04:02 UTC.
The content indicators and 2 positive source findings support the current Tdbank-themed impersonation classification.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260816-718500 Recipient: abuse@korbank.pl هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب