hoxtonbank.com
“Savings and Property - we'll help you achieve your goals”
The domain www.hoxtonbank.com was observed on 2026-07-12 and is classified as a high‑risk banking phishing site.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Zusammenfassung der Beweislage
The domain www.hoxtonbank.com was observed on 2026-07-12 and is classified as a high‑risk banking phishing site. The site presents a page titled “Savings and Property – we’ll help you achieve your goals,” mimicking a legitimate financial institution to lure victims into disclosing credentials. Threat intelligence assigns a risk level of high and marks the status as active.
The domain was registered on 2026-02-20 through Unstoppable Domains Inc. It uses the authoritative name servers ns5.nl.hostsailor.com and ns6.nl.hostsailor.com. DNS resolution points to the IPv4 address 194.36.191.196, which belongs to Host Sailor Ltd operating under AS60117 and is geolocated in the Netherlands.
The site serves an SSL certificate issued by Let’s Encrypt (R12), indicating the presence of HTTPS encryption but not authenticity. HTTP requests receive a 302 redirect response, a common technique to hide the final landing page. On VirusTotal the domain received a single positive detection out of 95 scanners, and it appears on one external blocklist. The Gridinsoft trust score is 0 out of 100, and PhishDestroy has already blocked the domain.
While the exact phishing payload has not been disclosed, the combination of a brand‑spoofing page title, active status, low trust score, and the presence on a phishing‑specific blocklist justifies immediate mitigation. Defenders should add 194.36.191.196 to outbound and inbound blocklists, enforce DNS sink‑hole rules for www.hoxtonbank.com, and monitor the associated name servers for future changes. Continuous re‑scanning with multiple AV engines is advised to capture any emerging detections. Organizations should also educate users about unsolicited requests for banking credentials that reference “Savings and Property” or similar phrasing.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Cloaking-Wert
- 0/6
- Last cloaking scan
- Server header seen by scanner
LiteSpeed
Scanner note: redirect: raw=redirect_302; http=302; via=https_proxy; location=./home/; server=LiteSpeed
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt