MALICIOUS — CRITICAL
aevitasbk[.]com
This domain, aevitasbk.com, is currently flagged as an active high-risk phishing site targeting financial services.
- VirusTotal
- 5/91
- Blocklists
- No stored match
- Disponibilité
- Dernier actif connu · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
aevitasbk.com — Dernier actif connu (HTTP 200). Type d'arnaque : Impersonation. Résumé des preuves: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_SPAM; PhishDestroy score 80/100. Bureau d’enregistrement: Ultahost.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
aevitasbk.com Fake Banking Portal Alert
This domain, aevitasbk.com, is currently flagged as an active high-risk phishing site targeting financial services.
This domain, aevitasbk.com, is currently flagged as an active high-risk phishing site targeting financial services. Infrastructure analysis reveals the domain was registered on September 3, 2025, through a hosting provider based in Germany, with an IP address of 159.100.6.5 under autonomous system AS214036. The domain resolves to nameservers ns1.ultahost.com through ns4.ultahost.com, and its MX records point solely to itself, a configuration often observed in phishing operations to intercept or redirect email communications. The SSL certificate is issued to an unrelated domain, globaloffshoremargin.com, which may indicate an attempt to obscure ownership or reuse compromised infrastructure. The domain has been detected by four security vendors on VirusTotal and appears on at least one security blocklist, reinforcing its classification as malicious. The page title, matching the domain name, suggests a generic banking or financial portal, though the exact content and targeted institution remain unconfirmed at this stage. The use of a recently registered domain, combined with hosting through a provider frequently associated with abusive activity, aligns with common phishing tactics designed to evade detection and maintain operational longevity. Defenders should treat this domain as hostile and prioritize blocking or monitoring any connections to 159.100.6.5 and its associated nameservers. Given the domain's active status and the presence of MX records, organizations should also assess whether internal email traffic is being directed to or through this infrastructure. The SSL certificate mismatch warrants further investigation, as it may indicate a broader pattern of domain or certificate abuse. While the specific phishing kit or payload is not yet identified, the domain's infrastructure and detection history provide sufficient evidence to classify it as a confirmed threat requiring immediate mitigation.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Couverture des données12 recorded checks
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of aevitasbk.com · checked Mar 2, 2026
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.