bank[.]cstdbn[.]online
“City Standard Bank || Banking services”
Зведення доказів
This domain, bank.cstdbn.online, was observed hosting a site with the page title “City Standard Bank || Banking services”. The title directly references a financial institution, indicating a classic banking credential‑stealing operation. The domain was registered on 21 February 2026 and presently resolves to the IP address 107.172.61.186, which is owned by HostPapa (AS36352) and geolocated in the United States. The SSL certificate applied to the host is rated R11, a low‑trust indication that the certificate is self‑signed or otherwise untrusted.
Automated scanning on VirusTotal recorded detections from 2 out of 93 security vendors, confirming that at least a minority of AV engines flag the site as malicious. Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on one external blocklist. PhishDestroy has already listed the host as blocked, and the overall status of the site is marked offline, suggesting that the phishing infrastructure may have been taken down or is temporarily unavailable. The available intelligence classifies the activity as a “Crypto Scam”, yet the page title and the observed brand reference point to a banking credential‑theft campaign.
No further technical artifacts such as login form URLs, JavaScript payloads, or redirect chains have been disclosed, leaving the exact phishing kit and data exfiltration method unknown. Defenders should continue to block the domain at network perimeter devices, update URL filtering and DNS sinkhole rules, and monitor for any re‑registration attempts that reuse the same sub‑domain pattern or host the same IP address. Because the IP belongs to a shared hosting provider, additional scrutiny of other domains hosted on 107.172.61.186 is advisable. Threat intelligence feeds should be enriched with the detection counts and trust scores noted here to improve correlation with future incidents targeting the same financial brand.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Криміналістичні дані
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога