online-giris[.]duckdns[.]org
“QNB Finansbank İnternet Şubesi”
online-giris.duckdns.org — Konten tidak tersedia. Peniruan identitas merek: Finansbank; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 17/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Registrar: DuckDNS.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, online-giris.duckdns.org, is identified as a brand impersonation phishing resource specifically targeting Finansbank customers. The page title, "QNB Finansbank İnternet Şubesi," mimics the legitimate online banking portal of the Turkish financial institution, attempting to deceive users into submitting sensitive credentials such as login details, personal identification numbers, or transaction authentication codes. The threat is categorized as elevated due to its direct targeting of financial services and the potential for significant monetary or identity theft consequences for affected individuals. Analysis indicates that the domain resolves to the IP address 94.183.168.45, hosted within the Iranian autonomous system AS213995 (Belenkii Ivan Alexandrovich). The domain is registered through DuckDNS, a dynamic DNS provider frequently exploited for malicious operations due to its low-cost and ephemeral nature. As of the latest assessment, 17 out of 95 security vendors on VirusTotal have flagged this domain as malicious, while it appears on at least one security blocklist. Notably, the domain lacks an SSL certificate, a common red flag in phishing campaigns where encryption is often absent to avoid detection or due to operational oversight. Users who have accessed online-giris.duckdns.org or submitted any credentials through the site should immediately cease all interaction and initiate incident response protocols. This includes changing passwords for Finansbank and any other accounts where identical credentials may have been reused. Affected individuals are advised to monitor their financial statements for unauthorized transactions and report suspicious activity to their financial institution. Additionally, enabling multi-factor authentication on all critical accounts can mitigate the risk of further compromise. Given the domain’s current offline status, users should remain vigilant for similar phishing attempts, particularly those leveraging dynamic DNS services or geolocated hosting in high-risk jurisdictions.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive