online-giris[.]duckdns[.]org
“QNB Finansbank İnternet Şubesi”
online-giris.duckdns.org — Контент недоступен (HTTP 502). Олицетворение бренда: Finansbank; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 17/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Регистратор: DuckDNS.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, online-giris.duckdns.org, is identified as a brand impersonation phishing resource specifically targeting Finansbank customers. The page title, "QNB Finansbank İnternet Şubesi," mimics the legitimate online banking portal of the Turkish financial institution, attempting to deceive users into submitting sensitive credentials such as login details, personal identification numbers, or transaction authentication codes. The threat is categorized as elevated due to its direct targeting of financial services and the potential for significant monetary or identity theft consequences for affected individuals. Analysis indicates that the domain resolves to the IP address 94.183.168.45, hosted within the Iranian autonomous system AS213995 (Belenkii Ivan Alexandrovich). The domain is registered through DuckDNS, a dynamic DNS provider frequently exploited for malicious operations due to its low-cost and ephemeral nature. As of the latest assessment, 17 out of 95 security vendors on VirusTotal have flagged this domain as malicious, while it appears on at least one security blocklist. Notably, the domain lacks an SSL certificate, a common red flag in phishing campaigns where encryption is often absent to avoid detection or due to operational oversight. Users who have accessed online-giris.duckdns.org or submitted any credentials through the site should immediately cease all interaction and initiate incident response protocols. This includes changing passwords for Finansbank and any other accounts where identical credentials may have been reused. Affected individuals are advised to monitor their financial statements for unauthorized transactions and report suspicious activity to their financial institution. Additionally, enabling multi-factor authentication on all critical accounts can mitigate the risk of further compromise. Given the domain’s current offline status, users should remain vigilant for similar phishing attempts, particularly those leveraging dynamic DNS services or geolocated hosting in high-risk jurisdictions.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание