saturnbarnksltd[.]com
“Home | Mobile Banking, Credit Cards, Mortgages, Auto Loan”
Сводка доказательств
saturnbarnksltd.com was observed hosting a page titled “Home | Mobile Banking, Credit Cards, Mortgages, Auto Loan”. The title suggests an attempt to impersonate a financial institution, consistent with the generic phishing classification. The domain was registered on 11 March 2026 through TuringSign Inc. d/b/a Cosmotown and is currently taken offline. DNS resolution points to the IPv4 address 213.111.152.217, which is announced by AS6698 Virtual Systems LLC located in Ukraine. The authoritative nameservers are ns5.hostcreed.com through ns8.hostcreed.com, indicating use of the Hostcreed hosting platform.
The site presented a TLS certificate issued by Let’s Encrypt, version R13, confirming the use of a freely‑issued certificate. Service banners reveal a web stack built on PHP running behind LiteSpeed, with client‑side libraries including Typekit, Modernizr, jQuery and support for HTTP/3. These components are common in legitimate sites and do not by themselves indicate compromise, but they confirm the technical footprint of the phishing infrastructure. Two of ninety‑five VirusTotal scanners flagged the domain, providing modest detection confidence. Independent blocklist monitoring shows the domain listed on a single security blocklist and actively blocked by the PhishDestroy service.
No additional public threat‑intel sources such as OTX or Safe Browsing entries were identified in the available data. Confidence in the phishing assessment is high based on the page title, registrar information, and blocklist presence, yet the limited number of VirusTotal detections and single blocklist entry leave some uncertainty regarding the breadth of victim exposure. Defensive actions should include adding the domain and its resolving IP to local blocklists, updating intrusion‑prevention signatures that reference the observed TLS fingerprint and HTTP/3 usage, and monitoring for any future re‑registration of the domain or similar naming patterns.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260311-FADFDE- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | saturnbarnksltd.com |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
VirusTotal
0 → 4
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of saturnbarnksltd.com · checked Mar 11, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание