savings[.]web[.]id
“Magnafx: One-Stop Global Investment Platform | Forex | Commodities | Stocks | Indices | Cryptocurre…”
Riepilogo delle prove
This domain, savings.web.id, is flagged for brand impersonation targeting users of the legitimate investment platform MagnaFX. Analysis indicates the site presents itself as a "One-Stop Global Investment Platform" offering forex, commodities, stocks, indices, cryptocurrencies, gold, and oil trading. The fraudulent nature is evident through its unauthorized use of the MagnaFX brand, designed to deceive victims into depositing funds or disclosing financial credentials under false pretenses. The domain is structured to appear as a legitimate trading portal, increasing the likelihood of successful social engineering attacks against inexperienced investors or those seeking high-yield opportunities. Infrastructure analysis reveals the domain was registered on June 25, 2026, through PT Jagoan Hosting Indonesia, a registrar commonly associated with recently observed fraudulent domains. It resolves to the IP address 188.114.96.3 and currently holds an SSL certificate issued by Google Trust Services, which may lend a false sense of security to visitors. Despite its active status and polished appearance, the domain has not been flagged by any of the 95 security engines on VirusTotal as of the latest scan, indicating it may still be in the early stages of deployment or evading detection through obfuscation techniques. No blocklist entries were identified at the time of analysis, further suggesting its novelty in the threat landscape. Users who have visited savings.web.id or interacted with its content should immediately cease all engagement and avoid providing any personal or financial information. If credentials or payment details were entered, affected individuals should revoke access to linked accounts, monitor for unauthorized transactions, and report the incident to their financial institution. Browser data, including cookies and cached content, should be cleared to mitigate persistent tracking or session hijacking risks. Security teams are advised to add the domain and its resolving IP to blocklists, while network administrators should inspect logs for connections to 188.114.96.3. Given the domain's impersonation of a financial service, victims may also consider filing a report with relevant cybercrime authorities to aid in broader disruption efforts.
Istantanea delle prove inviate
- Inviato
- Voci del registro
- 1
- ID del caso
PD-20260629-1FA4BE- Artefatto PDF
- Prova in PDF
Base giuridica
Testo completo delle prove
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
8 fonti esterne monitorate Nessuna corrispondenza
Tecnologie
5 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of savings.web.id · checked Jun 29, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo