Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
ag-dkb[.]site44[.]com
“DKB Banking”
Zusammenfassung der Beweislage
Analysis of ag-dkb.site44.com as of 24 July 2026 shows the host is actively serving content over HTTP with a 200 response and a valid TLS certificate issued by Let’s Encrypt (R12). The site resolves to 3.226.176.50, an address owned by Amazon.com, Inc. (AS14618) and therefore is hosted on Amazon Web Services infrastructure. DNS is delegated to four AWS‑managed name servers (ns‑1252.awsdns‑28.org, ns‑1932.awsdns‑49.co.uk, ns‑261.awsdns‑32.com, etc.), confirming the use of the AWS DNS service. The web server stack includes Varnish caching and the Bootstrap front‑end framework, as identified by fingerprinting tools. The domain was registered on 21 April 2012 through the registrar 1API GmbH, indicating a long‑standing registration that predates the current malicious activity. Threat intelligence records label the site as a generic phishing campaign targeting “DKB Banking”.
The page title returned by the server is “DKB Banking”, matching the advertised target. VirusTotal reports that 15 of 93 scanning engines have flagged the domain, providing independent corroboration of malicious intent. Additional security products have assigned a zero‑score trust rating (Gridinsoft 0/100) and the domain appears on at least one public blocklist. PhishDestroy has also listed the host as blocked, reinforcing the consensus that the site is being used for credential harvesting. While the available data confirms the presence of phishing‑related indicators, the specific payload, credential‑capture mechanism, and any associated command‑and‑control infrastructure have not been publicly disclosed.
No detailed behavioural analysis of the page content is available, and the extent of victim outreach (e.g., email campaigns, URL shorteners) remains unknown. Defenders should immediately add 3.226.176.50 and the fully qualified domain name ag‑dkb.site44.com to network‑level deny lists and web‑proxy block rules.
Momentaufnahme der übermittelten Beweise
- Gesendet
- Protokolleinträge
- 1
- Fall-ID
PD-20260214-DFA119- Titel der erfassten Seite
- DKB Banking
- PDF-Artefakt
- PDF-Beweis
Rechtsgrundlage
Vollständiger Beweistext
Acceptable Use Policy (AUP): The domain ag-dkb.site44.com is engaged in phishing activities, which directly contravenes the AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The hosting provider reserves the right to suspend or terminate services for violations, and the ongoing use of this domain for phishing constitutes a clear violation of these terms.
Applicable Laws (US):
Computer Fraud and Abuse Act (18 U.S.C. § 1030): This law prohibits unauthorized access to computers and networks, which is applicable in cases of phishing.
CAN-SPAM Act (15 U.S.C. § 7701 et seq.): This act addresses fraudulent email practices, including phishing, and mandates strict compliance to avoid penalties.
Wire Fraud (18 U.S.C. § 1343): Phishing schemes typically involve deceitful practices intended to secure financial gain, falling under this statute.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to liability under both your own policies and applicable federal laws. Non-compliance could result in regulatory scrutiny and potential legal repercussions.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | dogsabordo.com.br |
malicious | Sinkholed |
| Quad9 DNS | dogsabordo.com.br |
malicious | Sinkholed |
| Hagezi Threat Feed | dogsabordo.com.br |
malicious | Sinkholed |
| Cloudflare DNS | ag-dkb.site44.com |
malicious | Sinkholed |
| Hagezi Threat Feed | ag-dkb.site44.com |
malicious | Sinkholed |
| OpenDNS | ag-dkb.site44.com |
phishing | Phishing Block |
| Quad9 DNS | ag-dkb.site44.com |
malicious | Sinkholed |
| DNS4EU | ag-dkb.site44.com |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
ICANN OVERSIGHT
Registration: site44.com
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For the registrable domain site44.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of ag-dkb.site44.com · checked Mar 2, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt