knfbank[.]com
“Asset Financing, Easy Acount in Minutes”
Зведення доказів
This domain is flagged as an elevated-risk fake banking login portal designed to harvest credentials from unsuspecting users. Analysis indicates the infrastructure is specifically tailored for banking phishing, with page elements mimicking legitimate financial services, including promises of asset financing and quick account setup. The presence of typos such as 'Easy Acount' in the page title further suggests a lack of professionalism consistent with fraudulent operations. Infrastructure analysis reveals multiple high-risk indicators. The domain knfbank.com was registered on July 15, 2025, through Web Commerce Communications Limited, a registrar frequently associated with newly created phishing domains. It resolves to the IP address 107.173.193.235, which has been linked to other malicious activities. Security vendors on VirusTotal flagged the domain with 3 out of 95 detections, while Gridinsoft assigned a trust score of 0 out of 100. The domain appears on one security blocklist and was taken offline after being blocked by anti-phishing systems. These technical indicators collectively point to a coordinated effort to impersonate a legitimate banking institution. Users and organizations are advised to take immediate mitigation steps to prevent credential theft. Individuals who may have interacted with knfbank.com should reset passwords for any financial accounts, enable multi-factor authentication, and monitor transaction histories for unauthorized activity. Network administrators should block the domain and its associated IP address (107.173.193.235) at the firewall or DNS level to prevent access. Financial institutions should proactively warn customers about this specific threat and provide guidance on identifying phishing attempts. Given the domain's recent creation and offline status, continued vigilance is recommended as threat actors may re-deploy similar infrastructure under new domains.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
VirusTotal
1 → 3
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога