digitalccdbsi[.]univer[.]se
“digibank by DBS”
digitalccdbsi.univer.se — 未验证. 诈骗类型:Account Takeover. 证据摘要: VirusTotal 13/91 (alphaMountain.ai, BitDefender, ESET, Forcepoint ThreatSeeker, Fortinet); CF Radar malicious; PhishDestroy score 89/100. 注册商: 1 Api.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, digitalccdbsi.univer.se, is identified as a credential theft portal designed to harvest sensitive user login information. Analysis indicates the site likely mimics a trusted platform to deceive visitors into entering usernames, passwords, or other authentication details, which are then captured by threat actors for unauthorized access or financial fraud. The infrastructure and tactics observed align with targeted credential harvesting campaigns rather than broad phishing attempts. Infrastructure analysis reveals multiple high-confidence indicators supporting this assessment. The domain was registered on February 21, 2026, through 1Api GmbH, a registrar frequently associated with malicious activity. It resolves to the IP address 66.33.60.130, hosted on Amazon Web Services (AS16509), and is flagged by 17 out of 95 security vendors on VirusTotal. Additionally, the domain appears on one security blocklist and is actively blocked by PhishDestroy. The SSL certificate, issued by Let’s Encrypt (R13), provides minimal legitimacy while failing to offset the domain’s malicious intent. If you visited digitalccdbsi.univer.se or entered any credentials on the site, immediate action is required. First, terminate any active sessions and disconnect from the network to prevent further data exposure. Reset passwords for all accounts where the same credentials may have been used, prioritizing email, financial, and work-related platforms. Enable multi-factor authentication where available to add an additional layer of security. Monitor accounts for unusual activity, such as unauthorized logins or transactions, and report any suspicious behavior to the affected service providers. Finally, consider scanning your device for malware to ensure no secondary infections were introduced during the visit.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 7 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 置信度 100%React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 置信度 100%Next.js is a React framework for developing single page Javascript applications.
nextjs.org 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of digitalccdbsi.univer.se · checked Mar 2, 2026
网站配置分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。