www-simmonsbank[.]top
“Login”
www-simmonsbank.top — 内容不可用 (HTTP 502). 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 21/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); Spamhaus DBL_PHISH; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 95/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, www-simmonsbank.top, was identified as a high-risk credential phishing site impersonating Simmons Bank. The domain was created on February 21, 2026, and was reported as taken offline by July 23, 2026. The page title observed was 'Login', consistent with a credential harvesting page. Threat intelligence sources indicate strong evidence of malicious activity: 21 out of 93 security vendors on VirusTotal flagged the domain as malicious.
It appeared on four security blocklists: PhishDestroy, Polkadot, Enkrypt, and Codeesura. AlienVault OTX included the domain in one threat intelligence pulse. The domain resolved to IP address 144.31.244.50, located in Germany, and hosted by AS213877 U1 DIGITAL SERVICES LTD. The SSL certificate used was type R13.
At the time of analysis, the domain was confirmed offline, meaning the phishing site is no longer accessible. Defenders should verify that any users who may have accessed this domain have not submitted credentials, and monitor for any related subdomains or variations. The exact content of the login page was not analyzed, but the page title and scam type strongly indicate a credential theft operation targeting Simmons Bank customers. No additional brand, kit, or vendor details are available in the provided intelligence.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。