online-giris[.]duckdns[.]org
“QNB Finansbank İnternet Şubesi”
online-giris.duckdns.org — Inhalt nicht verfügbar. Markenidentität: Finansbank; Betrugstyp: Brand Impersonation. Zusammenfassung der Beweislage: VirusTotal 17/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Registrar: DuckDNS.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, online-giris.duckdns.org, is identified as a brand impersonation phishing resource specifically targeting Finansbank customers. The page title, "QNB Finansbank İnternet Şubesi," mimics the legitimate online banking portal of the Turkish financial institution, attempting to deceive users into submitting sensitive credentials such as login details, personal identification numbers, or transaction authentication codes. The threat is categorized as elevated due to its direct targeting of financial services and the potential for significant monetary or identity theft consequences for affected individuals. Analysis indicates that the domain resolves to the IP address 94.183.168.45, hosted within the Iranian autonomous system AS213995 (Belenkii Ivan Alexandrovich). The domain is registered through DuckDNS, a dynamic DNS provider frequently exploited for malicious operations due to its low-cost and ephemeral nature. As of the latest assessment, 17 out of 95 security vendors on VirusTotal have flagged this domain as malicious, while it appears on at least one security blocklist. Notably, the domain lacks an SSL certificate, a common red flag in phishing campaigns where encryption is often absent to avoid detection or due to operational oversight. Users who have accessed online-giris.duckdns.org or submitted any credentials through the site should immediately cease all interaction and initiate incident response protocols. This includes changing passwords for Finansbank and any other accounts where identical credentials may have been reused. Affected individuals are advised to monitor their financial statements for unauthorized transactions and report suspicious activity to their financial institution. Additionally, enabling multi-factor authentication on all critical accounts can mitigate the risk of further compromise. Given the domain’s current offline status, users should remain vigilant for similar phishing attempts, particularly those leveraging dynamic DNS services or geolocated hosting in high-risk jurisdictions.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt