loweii[.]org
Перевірка домену loweii.org на фішинг і безпеку
“BankID”
loweii.org — Контент недоступний (HTTP 502). Уособлення бренду: Bankidno; Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 18/94 (ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, CyRadar); URLQuery 2 det.; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Реєстратор: Internet Domain Servic….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, loweii.org, is identified as a phishing site designed to harvest BankID authentication credentials. BankID is a widely used electronic identification system, making it a high-value target for threat actors. Visitors to this site were likely presented with a fraudulent login interface mimicking legitimate BankID services, intended to deceive users into entering sensitive credentials such as usernames, passwords, or one-time codes. The stolen data could be used for unauthorized account access, financial fraud, or identity theft. Given the specificity of the target, this campaign poses a significant risk to individuals and organizations relying on BankID for secure authentication. Analysis indicates that loweii.org was registered on March 13, 2026, through Internet Domain Service BS Corp, a registrar frequently associated with malicious domain registrations. The domain resolves to the IP address 80.71.235.199, hosted under AS211673 (Mynymbox Hosting LLC) in the Netherlands, an autonomous system with a history of hosting phishing infrastructure. At the time of detection, 18 out of 95 security vendors on VirusTotal flagged this domain as malicious, confirming its classification as a generic phishing threat. Notably, the domain lacked an SSL certificate, which is unusual for legitimate financial services and further indicates its fraudulent nature. The domain was also listed on one security blocklist prior to being taken offline. If you visited loweii.org or entered any credentials on the site, immediate action is required to mitigate potential damage. First, revoke any active BankID sessions and contact your financial institution to report the incident and monitor for unauthorized transactions. Reset passwords and authentication tokens associated with BankID or any accounts linked to it. Enable multi-factor authentication (MFA) where available to add an additional layer of security. Scan your device for malware using updated security tools, as phishing sites may deploy additional payloads. Finally, report the incident to relevant cybersecurity authorities or your organization’s IT security team to assist in broader threat tracking and response efforts.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криміналістичні дані
Технології · 2 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of loweii.org · checked Mar 15, 2026
Докази та зовнішні звіти
PD-20260315-0F936A Recipient: abuse@mynymbox.io Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога