dnizinbanksii[.]duckdns[.]org
“dnizinbanksii.duckdns.org”
dnizinbanksii.duckdns.org — 内容不可用. 诈骗类型:Banking Phishing. 证据摘要: VirusTotal 16/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 95/100. 注册商: Gandi SAS.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of dnizinbanksii.duckdns.org indicates that the domain is being used for a banking phishing campaign. The page title returned by the host is identical to the domain name, providing no further contextual clues. The domain was registered on 12 April 2013 through Gandi SAS and is delegated to the DuckDNS dynamic DNS service using the three standard DuckDNS nameservers (ns1.duckdns.org, ns2.duckdns.org, ns3.duckdns.org). DNS resolution points to the IPv4 address 196.251.72.165, which is associated with a host located in South Carolina and listed as belonging to the entity “4445 Corporation”. The IP address currently appears on a single security blocklist and has been flagged by the PhishDestroy service as malicious.
VirusTotal has recorded detections from 16 of 93 security vendors for this domain, confirming a consensus among multiple scanning engines that the site hosts malicious content. The domain is also present on at least one public blocklist, reinforcing its classification as a threat. The limited blocklist presence suggests that detection is primarily driven by vendor scans rather than widespread abuse reports. No SSL/TLS information is available, and the site is presently offline, limiting real‑time verification of HTTP response codes or content. The lack of a live HTTP response means that Safe Browsing status cannot be verified at this time, and the absence of certificate data precludes assessment of trust scores.
The domain age of more than thirteen years may aid in evading some reputation‑based filters that prioritize newly created sites. Given the available evidence, defenders should continue to block traffic to both the domain and its resolved IP address at network perimeter devices. Updating URL filtering and DNS sinkhole configurations to include dnizinbanksii.duckdns.org and 196.251.72.165 will help prevent credential harvesting attempts.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | dnizinbanksii.duckdns.org |
malicious | Sinkholed |
| DNS0 Zero | dnizinbanksii.duckdns.org |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | dnizinbanksii.duckdns.org |
malicious | Sinkholed |
| Quad9 DNS | dnizinbanksii.duckdns.org |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。