dnizinbanksii[.]duckdns[.]org
“dnizinbanksii.duckdns.org”
dnizinbanksii.duckdns.org — Contenido no disponible. Tipo de estafa: Banking Phishing. Resumen de las pruebas: VirusTotal 16/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 95/100. Registrador: Gandi SAS.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of dnizinbanksii.duckdns.org indicates that the domain is being used for a banking phishing campaign. The page title returned by the host is identical to the domain name, providing no further contextual clues. The domain was registered on 12 April 2013 through Gandi SAS and is delegated to the DuckDNS dynamic DNS service using the three standard DuckDNS nameservers (ns1.duckdns.org, ns2.duckdns.org, ns3.duckdns.org). DNS resolution points to the IPv4 address 196.251.72.165, which is associated with a host located in South Carolina and listed as belonging to the entity “4445 Corporation”. The IP address currently appears on a single security blocklist and has been flagged by the PhishDestroy service as malicious.
VirusTotal has recorded detections from 16 of 93 security vendors for this domain, confirming a consensus among multiple scanning engines that the site hosts malicious content. The domain is also present on at least one public blocklist, reinforcing its classification as a threat. The limited blocklist presence suggests that detection is primarily driven by vendor scans rather than widespread abuse reports. No SSL/TLS information is available, and the site is presently offline, limiting real‑time verification of HTTP response codes or content. The lack of a live HTTP response means that Safe Browsing status cannot be verified at this time, and the absence of certificate data precludes assessment of trust scores.
The domain age of more than thirteen years may aid in evading some reputation‑based filters that prioritize newly created sites. Given the available evidence, defenders should continue to block traffic to both the domain and its resolved IP address at network perimeter devices. Updating URL filtering and DNS sinkhole configurations to include dnizinbanksii.duckdns.org and 196.251.72.165 will help prevent credential harvesting attempts.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | dnizinbanksii.duckdns.org |
malicious | Sinkholed |
| DNS0 Zero | dnizinbanksii.duckdns.org |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | dnizinbanksii.duckdns.org |
malicious | Sinkholed |
| Quad9 DNS | dnizinbanksii.duckdns.org |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.