rewardss[.]homes
“Bank of the Philippine Islands | BPI”
rewardss.homes — Контент недоступний (HTTP 502). Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 6/91 (ADMINUSLabs, alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. Реєстратор: Hefei Juming Network T….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, rewardss.homes, poses a direct financial credential theft risk by impersonating the official Bank of the Philippine Islands (BPI) login portal. Visitors are presented with a fraudulent interface designed to harvest banking usernames, passwords, and potentially one-time passcodes (OTPs). The site mimics legitimate banking authentication flows, increasing the likelihood of victim compliance. Given the domain's focus on a major financial institution, the threat extends beyond individual account compromise to potential large-scale fraud, including unauthorized fund transfers and identity theft. Analysis indicates the domain was registered on May 31, 2026, through Hefei Juming Network Technology Co., Ltd, a registrar frequently associated with malicious infrastructure. At the time of assessment, 6 out of 95 security vendors on VirusTotal flagged rewardss.homes as malicious, a detection rate consistent with active phishing campaigns. The domain resolves to the IP address 104.21.54.49, a Cloudflare proxy commonly used to obscure hosting origins. Additional technical indicators include the presence of Adobe Experience Manager and Salesforce Interaction Studio, technologies rarely deployed on legitimate banking portals but often exploited in phishing kits to enhance realism. The domain appears on three security blocklists and is actively blocked by multiple threat intelligence feeds. If you visited rewardss.homes or entered any credentials, immediately cease all interaction with the site. Change your BPI online banking password using a separate, trusted device and enable multi-factor authentication if not already active. Monitor your bank statements for unauthorized transactions and report any suspicious activity to BPI’s official fraud response team. Do not respond to any follow-up communications claiming to be from the bank, as these may be secondary phishing attempts. Consider placing a temporary fraud alert on your credit file to mitigate potential identity theft. Users who entered sensitive information should assume their credentials are compromised and take proactive steps to secure all linked accounts.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 8 identified
Adobe Experience Manager (AEM) is a content management solution for building websites, mobile apps and forms.
www.adobe.com 100% впевненостіJava is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com 100% впевненостіBootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 100% впевненостіSalesforce Interaction Studio (formerly Evergage) is a cloud-based software that allows users to collect, analyze, and respond to user behavior on their websites and web applications in real-time.
www.salesforce.com 100% впевненостіjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 100% впевненостіAdobe Dynamic Media Classic is a platform that enables customers to manage, enhance, publish, and deliver dynamic rich media content and personal experiences to consumers across all channels and devices, including web, print material, email campaigns, desktops, social, and mobile.
business.adobe.com 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of rewardss.homes · checked Jun 26, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога