online-giris[.]duckdns[.]org
“QNB Finansbank İnternet Şubesi”
online-giris.duckdns.org — Contenido no disponible. Suplantación de marca: Finansbank; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 17/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Registrador: DuckDNS.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, online-giris.duckdns.org, is identified as a brand impersonation phishing resource specifically targeting Finansbank customers. The page title, "QNB Finansbank İnternet Şubesi," mimics the legitimate online banking portal of the Turkish financial institution, attempting to deceive users into submitting sensitive credentials such as login details, personal identification numbers, or transaction authentication codes. The threat is categorized as elevated due to its direct targeting of financial services and the potential for significant monetary or identity theft consequences for affected individuals. Analysis indicates that the domain resolves to the IP address 94.183.168.45, hosted within the Iranian autonomous system AS213995 (Belenkii Ivan Alexandrovich). The domain is registered through DuckDNS, a dynamic DNS provider frequently exploited for malicious operations due to its low-cost and ephemeral nature. As of the latest assessment, 17 out of 95 security vendors on VirusTotal have flagged this domain as malicious, while it appears on at least one security blocklist. Notably, the domain lacks an SSL certificate, a common red flag in phishing campaigns where encryption is often absent to avoid detection or due to operational oversight. Users who have accessed online-giris.duckdns.org or submitted any credentials through the site should immediately cease all interaction and initiate incident response protocols. This includes changing passwords for Finansbank and any other accounts where identical credentials may have been reused. Affected individuals are advised to monitor their financial statements for unauthorized transactions and report suspicious activity to their financial institution. Additionally, enabling multi-factor authentication on all critical accounts can mitigate the risk of further compromise. Given the domain’s current offline status, users should remain vigilant for similar phishing attempts, particularly those leveraging dynamic DNS services or geolocated hosting in high-risk jurisdictions.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.