MALICIOUS — CRITICAL
finance39-ea95[.]pro
This domain presents an elevated risk due to its classification as a generic phishing threat.
- VirusTotal
- 11/91
- Blocklists
- 2 · MetaMask, SEAL
- Verfügbarkeit
- Inhalt nicht verfügbar · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
finance39-ea95.pro — Inhalt nicht verfügbar (HTTP 502). Zusammenfassung der Beweislage: VirusTotal 11/91 (alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker, Fortinet); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Registrar: NameCheap.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
finance39-ea95.pro — Generic Phishing Investigation
finance39-ea95.pro is a generic phishing domain flagged by 3/95 vendors on VirusTotal. Users should avoid visiting this domain and report it.
This domain presents an elevated risk due to its classification as a generic phishing threat. PhishDestroy analysts identified that finance39-ea95.pro was designed to impersonate legitimate financial services, luring users into disclosing sensitive information. Although the domain is currently offline, its recent activity and registration details suggest it was actively used for malicious purposes.
The domain was registered through NameCheap, Inc. on June 17, 2026, and resolved to IP address 188.114.96.3. It used an SSL certificate from Let's Encrypt (E8), which is commonly abused by phishers for a false sense of security. VirusTotal results show 3 out of 95 security vendors flagged the domain as malicious, and it appears on three security blocklists. The page title displayed a 404 Not Found error, indicating the site was likely taken down or its content removed. These technical indicators collectively confirm the domain's association with phishing campaigns.
Users who may have interacted with finance39-ea95.pro should monitor their accounts for suspicious activity and change passwords if any credentials were submitted. It is also recommended to enable multi-factor authentication on financial accounts and report the domain to relevant security teams. As a precaution, block the domain at the network level and ensure that email filters are updated to recognize similar domains. PhishDestroy continues to track this threat and will update advisories as new information emerges.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologien · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100 % KonfidenzCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.