saturnbarnksltd[.]com
“Home | Mobile Banking, Credit Cards, Mortgages, Auto Loan”
Zusammenfassung der Beweislage
saturnbarnksltd.com was observed hosting a page titled “Home | Mobile Banking, Credit Cards, Mortgages, Auto Loan”. The title suggests an attempt to impersonate a financial institution, consistent with the generic phishing classification. The domain was registered on 11 March 2026 through TuringSign Inc. d/b/a Cosmotown and is currently taken offline. DNS resolution points to the IPv4 address 213.111.152.217, which is announced by AS6698 Virtual Systems LLC located in Ukraine. The authoritative nameservers are ns5.hostcreed.com through ns8.hostcreed.com, indicating use of the Hostcreed hosting platform.
The site presented a TLS certificate issued by Let’s Encrypt, version R13, confirming the use of a freely‑issued certificate. Service banners reveal a web stack built on PHP running behind LiteSpeed, with client‑side libraries including Typekit, Modernizr, jQuery and support for HTTP/3. These components are common in legitimate sites and do not by themselves indicate compromise, but they confirm the technical footprint of the phishing infrastructure. Two of ninety‑five VirusTotal scanners flagged the domain, providing modest detection confidence. Independent blocklist monitoring shows the domain listed on a single security blocklist and actively blocked by the PhishDestroy service.
No additional public threat‑intel sources such as OTX or Safe Browsing entries were identified in the available data. Confidence in the phishing assessment is high based on the page title, registrar information, and blocklist presence, yet the limited number of VirusTotal detections and single blocklist entry leave some uncertainty regarding the breadth of victim exposure. Defensive actions should include adding the domain and its resolving IP to local blocklists, updating intrusion‑prevention signatures that reference the observed TLS fingerprint and HTTP/3 usage, and monitoring for any future re‑registration of the domain or similar naming patterns.
Momentaufnahme der übermittelten Beweise
- Gesendet
- Protokolleinträge
- 1
- Fall-ID
PD-20260311-FADFDE- PDF-Artefakt
- PDF-Beweis
Rechtsgrundlage
Vollständiger Beweistext
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | saturnbarnksltd.com |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
VirusTotal
0 → 4
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of saturnbarnksltd.com · checked Mar 11, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt