On 31 July 2026, the domain bnpparibas.mitarbeitervorteile.de was observed hosting a generic phishing campaign. The domain resolves to the IPv4 address 209.38.190.104. DNS queries return a heterogeneous set of authoritative name servers: a.ns14.net, b.ns14.net, c.ns14.net, d.ns14.net, ns1.linode.com, ns2.linode.com, and ns3.li, indicating the infrastructure is spread across multiple hosting providers. The domain is listed on one security blocklist and is actively blocked by the PhishDestroy service, confirming that defensive feeds have identified it as malicious.
VirusTotal analysis shows that nine out of ninety‑one scanning engines have flagged the domain, providing independent corroboration of its malicious nature. The limited number of detections suggests that the payload may be newly deployed or employs techniques that evade many scanners. No additional intelligence such as registrar information, SSL certificate details, or HTTP response codes is available in the current dataset, leaving the ownership and exact web content unverified. Defenders should prioritize adding the observed IP address and domain to internal blocklists, monitor DNS queries for the listed name servers, and enforce outbound traffic filtering to prevent connections to the host.
Continuous re‑scanning of the domain on multi‑engine platforms is advised, as detection rates may increase if the phishing site evolves. Organizations using email gateways or web proxies should ensure that phishing‑specific signatures, including those from PhishDestroy, are enabled to intercept attempts to lure credentials associated with the bnpparibas brand. Incident response teams should treat any credential submissions to this domain as compromised and initiate credential rotation and user awareness notifications.