सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 11। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

trojwesternonline[.]com[.]horizonnationalbk[.]com

“Trojan Western International Bank”

धमकी भरा फैसला गंभीर 87/100 साक्ष्य स्कोर
उपलब्धता सामग्री अनुपलब्ध नवीनतम अवलोकन में सामग्री अनुपलब्ध थी
VirusTotal detections: 11 (vendor total unavailable) Spamhaus DBL: DBL_SPAM URLQuery threat systems: 1 alert ब्रांड प्रतिरूपण: Facebook
11/03/2026 Facebook 1 Report Sent
रिपोर्ट सारांश

trojwesternonline.com.horizonnationalbk.com — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Facebook; घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 11 detections (engine total unavailable) (ADMINUSLabs, BitDefender, CRDF, CyRadar, Fortinet); URLQuery 1 alert; Spamhaus DBL_SPAM; PhishDestroy score 87/100. रजिस्ट्रार: NameSilo.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
9BBACF1F
स्कोर
87/100

Analysis of trojwesternonline.com.horizonnationalbk.com performed on July 25, 2026 indicates the domain is associated with a generic phishing campaign targeting users of Western International Bank. The page title returned by the host is "Trojan Western International Bank", confirming the intended victim brand. The domain was registered on March 11, 2026 through NameSilo, LLC and is hosted on an IP address 79.133.41.250 that resolves to an Ultahost, Inc. network in Germany (AS214036). Nameserver records point to ns1.ultahost.com and ns3.ultahost.com, consistent with the hosting provider. TLS is provided by a Let’s Encrypt R12 certificate, which validates the domain but does not imply legitimacy.

The site employed a stack that included YouTube embeds, Bootstrap framework, LiteSpeed server, OWL Carousel, jQuery, Popper, and HTTP/3 support, suggesting a fairly modern web stack. The domain appears on the PhishDestroy blocklist and has been flagged by 11 of 95 VirusTotal scanners, reinforcing the malicious classification. It is currently taken offline, which may be the result of takedown actions or hosting changes. No additional public blocklists beyond the single entry were observed, and safe‑browsing signals were not disclosed.

Uncertainty remains regarding the exact content served before the takedown, the presence of credential‑collection forms, and any downstream command‑and‑control infrastructure. Defenders should continue to block the domain at network perimeter, monitor DNS queries for the associated IP and nameservers, and add the domain to internal indicator lists. Because the SSL certificate is publicly trusted, users may be deceived by the lock icon; user education should stress that a valid HTTPS certificate does not guarantee authenticity. Ongoing observation of the registrar and IP range is advised in case the threat actor re‑hosts the phishing site on adjacent infrastructure.

VirusTotal
VirusTotal
11 det.
URLQuery
यूआरएलक्वेरी
1 threat alert
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
Let's Encrypt
आयु
5 mo
देखी गई स्थिति
सामग्री अनुपलब्ध 502
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज VirusTotal 11 detections · vendor total unavailable यूआरएलक्वेरी 1 threat-system alert फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक 14 जाँच पूरी — कोई ब्लॉक नहीं TLS valid certificate, 55d कौन है 5 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
Registrar context NameSilo
Stored registration data identifies NameSilo as the registrar. PhishDestroy maintains separate registrar investigations; that broader material is contextual and is not an independent detection for this domain.
Review source investigation
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU trojwesternonline.com.horizonnationalbk.com malicious Sinkholed

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
15/15
Sent Report Recorded
Stored sent-report record for registrar NameSilo, LLC, hosting provider, 3 abuse contacts
abuse@first-colo.netabuse@namesilo.comu-abuse@ultahost.com
11/03/2026

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

पेज शीर्षक
Trojan Western International Bank
Impersonates
Facebook Gmail Instagram LinkedIn Mastercard Visa
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 55 days

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN LiteSpeed · AS214036 Ultahost, Inc.
IP प्रतिष्ठा abuse score 0/100 1 report checked 14/07/2026
Registrar (base domain) NameSilo US(US) PhishDestroy Investigation
दुरुपयोग संपर्कabuse@first-colo.net, abuse@namesilo.com, u-abuse@ultahost.com
IP पता 79.133.41.250 DE
भौगोलिक स्थानDE Mörfelden-Walldorf, DE
नेटवर्कAS214036 · Ultahost, Inc.
रिवर्स IPviewdns.info → rapiddns.io →
Registration (base domain)horizonnationalbk.com · निर्मित 11/03/2026 (163d)
HTTP स्थिति502 Error
पहली अनुपलब्धता तक का समय 4 days
हम क्या मापते हैं पहली संग्रहीत दुरुपयोग रिपोर्ट से लेकर पहली बार अवलोकन तक कि सामग्री अनुपलब्ध थी, बीता हुआ समय। इससे कारण स्थापित नहीं होता.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला11/03/2026
DOM Analysisanalyzed 29/07/2026score 73/1006 brand signals
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://trojwesternonline.com.horizonnationalbk.com/
नेमसर्वरns3.ultahost.com
TLS Fingerprint
TLS Observationvalid from 04/02/2026scanned 15/03/2026
TLS SAN Domainsautodiscover.horizonnationalbk.comautodiscover.trojwesternonline.comcpanel.horizonnationalbk.comcpanel.trojwesternonline.comcpcalendars.horizonnationalbk.comcpcalendars.trojwesternonline.comcpcontacts.horizonnationalbk.comcpcontacts.trojwesternonline.comctruncs.com.horizonnationalbk.comhorizonnationalbk.commail.horizonnationalbk.commail.trojwesternonline.comtrojwesternonline.comumfibkonline.horizonnationalbk.comwebdisk.horizonnationalbk.com+8
Case ID
ICANN OVERSIGHT Registration: horizonnationalbk.com

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For the registrable domain horizonnationalbk.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।
तकनीकें · 7 identified
YouTube
Bootstrap
UI frameworks

Popular CSS framework for responsive, mobile-first web development.

LiteSpeed
Web servers

High-performance web server compatible with Apache configurations.

OWL Carousel
JavaScript libraries

Touch-enabled jQuery plugin for responsive carousel sliders.

jQuery
JavaScript libraries

Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.

Popper
HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

11 detections recorded · vendor total unavailable
View on VT
Last analyzed
ADMINUSLabs
BitDefender
CRDF
साइरेडार
Fortinet
G-Data
कास्परस्की
Lionic
SOCRadar
सोफोस
वेबरूट
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of trojwesternonline.com.horizonnationalbk.com · checked Mar 11, 2026

51
Needs Work
Performance
FCP
1.8s
First Contentful Paint
LCP
8.48s
Largest Contentful Paint
CLS
0.409
Cumulative Layout Shift
TBT
26ms
Total Blocking Time
SI
5.26s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

साक्ष्य और बाहरी रिपोर्टें

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260311-5A9CAD Recipient: abuse@first-colo.net
Page title stored with report: Trojan Western International Bank
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 288.8 KB

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/trojwesternonline.com.horizonnationalbk.com"
  title="PhishDestroy threat report for trojwesternonline.com.horizonnationalbk.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।