postfinance[.]actions[.]atwork[.]ai
“atwork AI Action Suggestion”
Kanıt özeti
The domain postfinance.actions.atwork.ai has been assessed as an elevated risk for brand impersonation. This type of threat typically involves the creation of a deceptive website designed to mimic a legitimate brand, with the intent of tricking users into divulging sensitive information or performing unauthorized actions.
Infrastructure analysis reveals that the domain was registered through GoDaddy.com, LLC on February 27, 2026. The SSL certificate is issued by DigiCert Inc / GeoTrust TLS RSA CA G1, which may give a false sense of security to unsuspecting visitors. The domain resolves to the IP address 20.105.232.15, located in the Netherlands (NL) and associated with AS8075, Microsoft Corporation. Analysis on VirusTotal indicates that 17 out of 95 security vendors flag this domain as malicious. Additionally, the domain appears on one security blocklist and has been blocked by PhishDestroy. The page title, 'atwork AI Action Suggestion,' further suggests a sophisticated attempt to impersonate a legitimate service.
To mitigate the risks associated with this brand impersonation scam, users are advised to verify the authenticity of any communication or link purportedly from PostFinance or related services. Implementing multi-factor authentication (MFA) on all accounts can significantly reduce the likelihood of unauthorized access. Organizations should also train employees to recognize and report phishing attempts, and consider deploying advanced email filtering and web protection solutions to block such domains automatically.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260227-05D8AB- Yakalanan sayfa başlığı
- atwork AI Action Suggestion
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | postfinance.actions.atwork.ai |
malicious | Sinkholed |
| Cloudflare DNS | postfinance.actions.atwork.ai |
malicious | Sinkholed |
| OpenDNS | postfinance.actions.atwork.ai |
phishing | Phishing Block |
| Quad9 DNS | postfinance.actions.atwork.ai |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
VirusTotal
14 → 17
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin