americavaultbank[.]com
“America Vault Bank – Spend and save with confidence”
Riepilogo delle prove
The domain americavaultbank.com was registered on February 21, 2026 through Dynadot LLC and is currently resolving to the IPv4 address 198.251.83.106, which is assigned to AS53667 FranTech Solutions in the United States. The site presents the page title “America Vault Bank – Spend and save with confidence,” suggesting an attempt to masquerade as a legitimate financial institution. The SSL certificate is issued by Let’s Encrypt (R13), providing a valid TLS handshake but offering no authentication of the underlying entity. An HTTP GET returns status code 200, indicating the server is actively serving content. Threat intelligence from VirusTotal shows that three of ninety‑three scanning engines have flagged the domain, confirming that at least a minority of security products consider it malicious. The site scores 0 out of 100 on the Gridinsoft trust metric, reinforcing the high‑risk assessment.
It is listed on one public security blocklist and is actively blocked by the PhishDestroy feed, demonstrating that some downstream defenses already recognize the threat. Infrastructure analysis reveals a typical phishing stack: the web server runs LiteSpeed and hosts a WordPress instance backed by MySQL and PHP. Front‑end libraries such as jQuery, jQuery Migrate, Font Awesome and Smartsupp are detected, which are commonly bundled in low‑cost phishing kits. The nameservers ns25.my-control-panel.com and ns26.my-control-panel.com are generic control‑panel services, a pattern often observed in fast‑flux or disposable hosting. The specific scam type is identified as an “Investment Scam,” yet no additional content has been publicly disclosed, so the exact lure (e.g., fraudulent investment offers, fake account portals) remains unknown.
Consequently, defenders cannot confirm whether credential harvesting forms or malicious downloads are present. Recommended defensive actions include adding americavaultbank.com and its resolving IP 198.251.83.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Analisi della configurazione del sito
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo