reimtrust[.]com
“ReimTrust Bank – Personal & Business Banking”
reimtrust.com — Скрытый · достижимый (HTTP 502). Олицетворение бренда: Facebook; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 2/95 (alphaMountain.ai, Fortinet); cloaking observed; PhishDestroy score 56/100. Регистратор: Web Commerce Communica….
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
On July 22, 2026, the domain reimtrust.com was identified as a brand‑impersonation site targeting Facebook. The site was registered on June 5 2025 through Web Commerce Communications Limited and resolves to the IP address 107.173.193.235, which belongs to AS36352 (HostPapa) located in the United States. Infrastructure analysis shows the domain is hosted on a LiteSpeed web server running a WordPress stack with MySQL, PHP, UIKit, jQuery, jQuery Migrate and Font Awesome libraries. The domain is served without an SSL certificate and uses the authoritative nameservers ns1.bthostcloud.com and ns2.bthostcloud.com.
The public page title returned by the server is “ReimTrust Bank – Personal & Business Banking,” which does not reference the impersonated brand and suggests the site may have been repurposed or is in a transition state. Security telemetry indicates the domain appears on a single blocklist and has been actively blocked by PhishDestroy. VirusTotal scans report that two of ninety‑five scanning engines flagged the domain, confirming the presence of malicious indicators despite the relatively low detection count. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the assessment of high risk.
The site’s current HTTP status is offline, which limits immediate interaction but does not remove the threat of future re‑activation. Defenders should add reimtrust.com to internal block lists, monitor DNS queries for the associated IP and nameservers, and ensure that any outbound connections to the host are denied. Continuous re‑scanning with multi‑engine services is recommended to capture any changes in the malicious payload, especially if the site is brought back online. Because the page title does not contain Facebook branding, automated content‑matching may miss this indicator; therefore, correlation with the known brand‑impersonation tag and blocklist entries is essential for reliable detection.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 9 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org 100% уверенностиQuery Migrate is a javascript library that allows you to preserve the compatibility of your jQuery code developed for versions of jQuery older than 1.9.
github.com 100% уверенностиjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание