brinprimefn[.]com[.]growthcreditfn[.]com
“Brin Prime Finance Bank | Online Banking & Payment”
brinprimefn.com.growthcreditfn.com — Conteúdo indisponível (HTTP 502). Representação da marca: Across; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 10/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); PhishDestroy score 80/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain brinprimefn.com.growthcreditfn.com was registered on February 21, 2026 and is currently reported as offline. DNS resolution points to IP address 198.12.93.82, which is hosted in the United States under autonomous system AS36352 belonging to HostPapa. The hosting provider’s reputation is not directly indicated, but the IP appears on a single security blocklist and has been actively blocked by the PhishDestroy mitigation service. The site presented an SSL certificate labeled R11, a rating that typically denotes low trustworthiness and suggests the certificate may be self‑signed or otherwise unvalidated. The page title returned by the server, "Brin Prime Finance Bank | Online Banking & Payment," aligns with a brand‑impersonation attempt, and the intelligence tags the activity as a crypto‑related scam targeting a broad audience (brand target "across").
Detection engines provide mixed signals: ten out of ninety‑three VirusTotal‑linked security vendors flagged the domain as malicious, indicating a moderate level of consensus among scanners. Gridinsoft assigned a trust score of zero out of one hundred, reinforcing the perception of high risk. Despite these indicators, the domain’s presence on only one public blocklist suggests limited visibility in some threat‑sharing feeds.
Uncertainty remains regarding the exact payload or luring mechanisms, as no detailed page content or malware analysis has been published. The offline status prevents real‑time verification of the site’s behavior, and the lack of additional blocklist listings means that some security products may not yet recognize the domain.
Defenders should proactively block the IP address 198.12.93.82 and the fully qualified domain name in network firewalls and DNS filtering solutions. Adding the domain to internal and external blocklists, especially those used by email gateways and web proxies, will reduce exposure.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo