fidelity[.]ihsbonline[.]com
“Fidelity IHS - Money Transfer & Online Banking”
fidelity.ihsbonline.com — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: Across; घोटाले का प्रकार: Banking Phishing. साक्ष्य सारांश: VirusTotal 2/95 (Fortinet, Gridinsoft); PhishDestroy score 56/100. रजिस्ट्रार: NameCheap.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain fidelity.ihsbonline.com was observed hosting a fraudulent site that presents the page title “Fidelity IHS - Money Transfer & Online Banking”. The site is classified as a banking phishing campaign that attempts to impersonate the Fidelity brand, as indicated by the page title and the “Brand target: across” entry. The domain was registered through NameCheap, Inc. on 1 October 2024 and resolves to the IP address 135.125.140.191, which belongs to the OVH SAS network (AS16276) located in Germany. No TLS certificate is deployed, meaning traffic is served over plain HTTP. The infrastructure uses three custom nameservers—ns1.cloudoon.com, ns2.cloudoon.net, and ns3.cloudoon.org—suggesting a self‑managed hosting environment.
The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy service. VirusTotal scans show that two out of ninety‑five scanners flagged the domain, reinforcing the malicious assessment. A Gridinsoft trust score of 0 / 100 further indicates a lack of legitimacy. The site’s current status is listed as offline, which may be the result of takedown actions or automated sinkholing. Evidence gaps remain: the exact content of the landing page has not been captured, so the presence of credential‑capture forms or redirects cannot be confirmed.
Additionally, no public Safe Browsing or OTX entries were referenced in the provided data, limiting insight into broader detection coverage. Defenders should continue to monitor the IP 135.125.140.191 and associated nameservers for any re‑use, enforce outbound filtering for the domain and related hostnames, and ensure that users are warned about unsolicited communications that reference Fidelity services. Blocking the domain at the DNS level and adding the IP to threat‑intel feeds will help prevent future exposure. Ongoing collaboration with registrars and hosting providers is recommended to accelerate takedown of any revived infrastructure.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
Registration: ihsbonline.com
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For the registrable domain ihsbonline.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।