acornbnk[.]live[.]luminacapital[.]pro
“Home - Acorn Bank”
acornbnk.live.luminacapital.pro — Контент недоступен (HTTP 502). Олицетворение бренда: Foundation; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 2/93 (alphaMountain.ai, Fortinet); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 56/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of acornbnk.live.luminacapital.pro indicates that the domain was registered on 21 February 2026 and is presently taken offline. The site presented the page title “Home – Acorn Bank,” suggesting an attempt to masquerade as a financial institution, and the intelligence tags it as a brand‑impersonation campaign targeting the “foundation” brand. Network resolution points to the IPv4 address 176.123.0.199, which is announced by AS200019 belonging to ALEXHOST SRL and geolocated to Maryland, United States. The TLS certificate is rated R10, and the Gridinsoft trust score is 0 / 100, reinforcing the malicious nature of the host.
Scanning on VirusTotal returned detections from 2 of 93 security vendors, demonstrating that at least a small subset of AV engines have identified malicious behavior. The domain appears on a single public blocklist and is explicitly listed by the PhishDestroy service, confirming that external threat‑intelligence feeds consider it abusive. No additional evidence such as Safe Browsing or OTX identifiers was supplied. Defenders should treat the domain as hostile: block DNS resolution for acornbnk.live.luminacapital.pro, deny outbound connections to 176.123.0.199, and add the IP to network‑level blacklists.
Monitoring for future re‑activation is advisable, as the underlying hosting provider (ALEXHOST SRL) may be reused for other campaigns. Because the page title references “Acorn Bank,” any email or web‑based lure that claims to be from that institution should be scrutinized, especially if it asks for credential input. Continuous feed updates from PhishDestroy and similar blocklist services will help maintain coverage, and analysts should correlate any observed traffic with the known SSL rating and trust‑score anomalies. Until the domain reappears, the current evidence justifies an elevated risk rating and proactive containment.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание