polonus
2
Hi Be Secure,
If this has to do with banking and banking threat, the first and second address will have to go here: https://forum.avast.com/index.php?topic=83592.0 as Avast Team Member, Vlk, particularly asked users to list their online banking sites in that thread to better protect against such threats.
The first PHISH you mention has been a threat for over a year and is being flagged by Google safebrowsing (so users of Google Chrome and firefox are already protected if they aren’t that stupid to click through), Bitdefender TrafficLight, PhishTank and others flag.
The second live threat has been reported on VirusWatch MX → http://support.clean-mx.com/clean-mx/phishing.php?domain=capitalf-bnk.co.uk&sort=id%20DESC (is alive and PHISHing!). Should be reported also to WOT, and I have just done so under my alter ego, luntrus.
The other one is a PHISH allright, but not related to a banking site → http://support.clean-mx.com/clean-mx/phishing.php?domain=abnehmen-wundermittel.com&sort=id%20DESC The query there is n 52.28.153.73 a notorious IP in that respect, see: http://permalink.gmane.org/gmane.comp.security.phishings/68186 The one you mentioned is blocked for me by Bitdefender TrafficLight in the Google Chrome browser.
polonus
polonus
3
Now some of those given by GMane are not flagged by AOS and others as well, for instance -polypouch.co.uk (not banking related!).
The Netcraft Website Riskstatus (9 red out of 10) is quite clear: http://toolbar.netcraft.com/site_report?url=http://209.61.231.58 This site is PHISHINg via leadforensics dot com → http://www.domxssscanner.com/scan?url=http%3A%2F%2Fpolypouch.co.uk See bad web rep: https://www.mywot.com/en/scorecard/leadforensics.com?utm_source=addon&utm_content=rw-viewsc MyWot.com Reputation Ratings 26
Alive and now one hour old, so you see such abuse can be short-termed or 209.61.231.58
Tracking info goes insecure to At least 8 third parties know you are on this webpage.
-www.google.com
-www.google-analytics.com Google
-www.saas-eue-1.com redirecting to -leadforensics.com
-www.polypouch.co.uk
-polypouch.co.uk
-x.translateth.is (translating button) info via Tracker SSL extension in Google Chrome.
polonus (volunteer website security analyst and website error-hunter)
Hello.
https://zonasegura1.bn.com.pe/BNWeb/Inicio It will not be blocked
Virus lab has now classified these websites.
https://zonasegura1.bn.com.pe/BNWeb/Inicio
appears to be on the bn.com.pe domain, so they believe this website to be correct.
capitalf-bnk.co.uk/ has now been blocked
abnehmen-wundermittel.com/ has now been blocked