Corvus
Evidence · Source Records · Forensic Audit Trail

Evidence

Every claim in this report traces back to one of 40 evidence records below. Each was captured passively during recon, hashed at capture for chain-of-custody, and graded per the Admiralty Scale (NATO STANAG 2511). Click any ev_xxx chip elsewhere in the report to jump straight to its source record.

40
Records
26
Sources
38
High Grade
1
Moderate
1
Low Grade
2026-05-26 → 2026-05-26
Captured
40 of 40 shown
ev_001 B-2
Source wikipedia_summary · Captured
Deutsche Bank AG is a German multinational investment bank and financial services company headquartered in Frankfurt. It is dual-listed on the Frankfurt Stock Exchange and the New York Stock Exchange.
SHA-256 2b00f0bbee367505be07e67ad72b1e6a2016a0f7ab8c231c5b481d9d3e8cc4a1
ev_002 A-1
Source gleif_search · Captured
LEI 7LTWFZYICNSX8D621K86 — DEUTSCHE BANK AKTIENGESELLSCHAFT — Taunusanlage 12, 60325 Frankfurt am Main, DE — HRB 30000 — Legal form 6QQB — Created 1952-11-10 — Status ACTIVE — FULLY_CORROBORATED — S&P 410467 — 73 BIC codes including DEUTDEFFXXX, DEUTUS33XXX, DEUTGB22XXX, DEUTHKHHXXX, DEUTJPJTXXX, DEUTSGSGXXX, DEUTINBBXXX, DEUTCHZZXXX, DEUTKYKXXXX, DEUTAEAAXXX, etc.
SHA-256 f695bb81bdab469025042f92b656275e27c45d8c3d503c7264527893c0952fff
ev_003 A-1
Source rdap_domain · Captured
DB.COM — Registrar: CSC Corporate Domains Inc. (IANA 299) — Registered 1997-09-02 — Expires 2026-09-01 — Status: client/server transfer prohibited, server delete/update prohibited — Nameservers: NS8.DB.COM through NS17.DB.COM — DNSSEC delegationSigned: false — Registrant org per VT WHOIS: Deutsche-Bank Group (DE)
SHA-256 f7d32c46a67d18880f04872b281d6958ec4534218ceae2536d6b76ab2330ea8a
ev_004 A-1
Source dns_mail_auth · Captured
db.com SPF: v=spf1 ip4:160.83.0.0/16 ~all | DMARC: v=DMARC1; p=reject; sp=reject; adkim=s; fo=1; ri=3600 (Proofpoint-fronted RUA/RUF) | MX: smtp13/14/15/22/24.db.com pri 10, smtp23.db.com pri 15
SHA-256 842910cb68892dd9805a82f98bda616385fd2d15dcb1481b6cec49e488c91697
ev_005 A-1
Source certspotter_enumerate · Captured
CertSpotter enumeration of *.db.com — 280 unique subdomains across 100 sampled certs. Key surfaces: cidp-eu, autodiscover, cas-hybrid.de, cashmanager (+ sng/uk/us), dbsurface, dbras, dbvideokyc.uat, dbdigitalonboarding.sit/uat, jss-sit/uat, securewebmail (+ uat), miles-and-more-kreditkarte, autobahnfx (+ staging), push.autobahn, seal.autobahn, sg-teams-01, video, collab-edge.video, ecmsyndicate, ideal2-acquirer-signing-live, edge2016-1..10, hybrid-de, exp-e-cluster.uk/us, frainexchb/p1..5.de,...
SHA-256 a66b70c09cb0e6c2b11fb4261e482939576b71b0f68cd825af5a56838211b414
ev_006 A-1
Source rdap_ip · Captured
34.98.101.189 — NetRange 34.64.0.0/10 GOOGL-2 — Google LLC, 1600 Amphitheatre Parkway, Mountain View CA 94043 — Direct Allocation 2018-09-28 — POC google-cloud-compliance@google.com — Comment: 'The IP addresses under this Org-ID are in use by Google Cloud customers'
SHA-256 d964e1dc9f489d6fd1bf2a0cbd36876eaeb4ecb02404cf71477c09ddc2b431c0
ev_007 A-2
Source greynoise_community · Captured
34.98.101.189 — noise: false, riot: true, classification: benign, name: Google Cloud, last_seen: 2026-05-26 — Classification: RIOT-listed benign service
SHA-256 8df6c2ac9810bf51adc7d3ba061dff07f7eb888a660d319520fae1e8b29bb27c
ev_008 B-2
Source vt_ip · Captured
34.98.101.189 — ASN 396982 Google LLC GOOGLE-CLOUD-PLATFORM — 0/0/55/36 malicious/suspicious/harmless/undetected — JARM 29d3fd00029d29d00042d43d00041d6f940079659edb62e1c38c38bd26ee84 — TLS cert subject: O=DEUTSCHE BANK AG, CN=www.db.com, STREET=Taunusanlage 12, HRB 30000, C=DE
SHA-256 fdb1559fbc6cb80698ece2be51a0e4aec09d9ed8e66464e40d8a9e473978d7f1
ev_009 B-2
Source ipapi_lookup · Captured
34.98.101.189 — US, Missouri, Kansas City — lat 39.0997 lon -94.5785 — Google LLC, Google Cloud, AS396982
SHA-256 500afeaf5757ea7898bb6ec06590a11c1b8e5bc6c5c66985fb75f38fec1c2043
ev_010 A-2
Source hackertarget_asn · Captured
160.83.0.1,8373,160.83.0.0/19,DEUBA-NET Germany, DE
SHA-256 430d4a89ea58a9de930331dbc468391a22cd624001a541c6a98e69afab8d931b
ev_011 A-1
Source rdap_asn · Captured
AS8373 DEUBA-NET — RIPE registered 2002-09-23 — Org = Deutsche Bank AG, Taunusanlage 12, 60325 Frankfurt — Tech: DB IP Services (dns.admin@db.com, Taunusanlage 12) — Admin: Reiner Schaefer (Postfach 65760 Eschborn) — Abuse-C: Alfred-Herrhausen-Allee 16-24, 65760 Eschborn; dns.admin@db.com
SHA-256 85a7805a2693bff5bbf4ab5f51e35dc8ae717de0701af46670988aaee653a802
ev_012 A-1
Source rdap_asn · Captured
AS15769 — RIPE — Remark: 'Deutsche Bank Internet Operations, London' — Org = Deutsche Bank AG Taunusanlage 12 Frankfurt — Tech: Anna Grasser (Alfred-Herrhausen-Allee 16-24, 65760 Eschborn, GTO IES Network Engineering) and Joerg Schwarzwaelder (Taunusanlage 12 60325 Frankfurt) — Last changed 2021-07-05
SHA-256 cf659ec64826e68aefefc5e7044e7e78a4c1395dc61361289a49d109189f4a5d
ev_013 A-1
Source rdap_asn · Captured
AS2824 DB-NA-1 — ARIN registered 1993-08-17 — Org = Deutsche Bank AG, 2 Peekay Drive, Clifton NJ 07014 US (Digital Realty NJ EWR21 datacenter — operator wikidata Q5275969) — POC: DNS ADMIN Taunusanlage 12 Frankfurt 60325 (dns.admin@db.com) — Admin: Reiner Schaefer reiner.schaefer@db.com Theodor-Heuss-Allee 72 Frankfurt — Registration comment http://www.db.com
SHA-256 08b96337f3ae9872302a5a96cdca9a1424285789e18c1174902e892da5d10234
ev_014 B-2
Source vt_domain · Captured
db.com — 0/0/60/31 malicious/suspicious/harmless/undetected verdicts — reputation -1 — TLS cert SHA256 b3e3478b3e61e75b8f71513f455a8561cc30c97955cc8e576c25692d1e4be285 — issuer DigiCert EV RSA CA G2 — validity 2026-04-12 to 2026-10-27 — JARM 29d3fd00029d29d00042d43d00041d6f940079659edb62e1c38c38bd26ee84 — popularity rank Cisco Umbrella 18606 Cloudflare Radar 10000 Majestic 4618
SHA-256 cf1a0b50ce3c8e4c9c9e9363f3179f03221f4ee1429098bbb954146581ff2253
ev_015 A-1
Source gleif_record · Captured
LEI 529900VM3464806ERS69 — DWS Group GmbH & Co. KGaA — Mainzer Landstraße 11-17, 60329 Frankfurt am Main — HRB 111128 — Legal form T0YJ — Created 2016-06-29 — Status ACTIVE — S&P 538321028 — OCID de/M1201_HRB111128
SHA-256 2e2ec13e996cb697067b8730a61de02f62ae7ae99c3b5bfdbc2e8942efb1d268
ev_016 B-2
Source wikipedia_summary · Captured
DWS Group GmbH & Co. KGaA, commonly known as DWS, is a German asset management company. It previously operated as part of Deutsche Bank until 2018 where it became a separate entity through an initial public offering on the Frankfurt Stock Exchange. It is currently headquartered in Frankfurt, Germany and is a constituent member of the MDAX index.
SHA-256 dc7feffc961dc502724cd53ac5412bc826918ae7668dd1854ac049759cbd5982
ev_017 A-1
Source gleif_direct_children · Captured
326 direct LEI children of Deutsche Bank AG across 40+ jurisdictions. Top countries: US (91), DE (66), GB (27), LU (25), KY (17), NZ (7), IN (7), IT (7), SG (6), JP (5). Includes DWS Group, Deutsche Bank Europe GmbH, norisbank GmbH, DB Capital Markets (Deutschland) GmbH, Deutsche Bank Contingent Capital Trust III/IV, RREEF entities, DB ASTER LLC/INC, Azurix Corp., 87 LEONARD DEVELOPMENT LLC, NEW 87 LEONARD LLC, CINDA-DB NPL SECURITIZATION TRUST 2003-1, Deutsche Cayman Ltd., DEUTSCHE ALTERNATI...
SHA-256 f887a3359e2ebd687109aae2699e37224c363d485fda85c4d7014e55c939f750
ev_018 A-1
Source gleif_record · Captured
LEI 529900WMBOJTFWCJ6Z71 — norisbank GmbH — Bundeskanzlerplatz 4, 53113 Bonn, NRW (moved 2025-03-31) — HRB 21185 Bonn — Legal form 2HBR (GmbH) — Created 1957-04-08 — Status ACTIVE — BIC NORSDE51XXX — S&P 44297176
SHA-256 7ee91f447e7906badda4b899cbf80b3f990780a87c788f7905c45de97708a683
ev_019 A-1
Source gleif_record · Captured
LEI 213800QILIUD4ROSUO03 — Deutsche Bank Europe GmbH — Taunusanlage 12, 60325 Frankfurt — HRB 87506 — Legal form 2HBR (GmbH) — Created 2010-02-17 — Status ACTIVE — BIC DEUTDE5XXXX — S&P 224020398
SHA-256 6f9bb17995e434710a7a9ea216a551653c5fe916c8c31ebacca2ca49dcdb61fa
ev_020 B-2
Source wikidata_sparql · Captured
Wikidata P749 (subsidiary of) Q66048 returns: Deutsche Postbank (Q708835, 1989), DB Privat- und Firmenkundenbank (Q1202176, 1995), Norisbank (Q1999153, 1965), Deutsche Bank Polska (Q9206601, 1995), Numis (Q55627117), Deutsche Beamten-Zentralbank (Q107102864, 1924), Aktiengesellschaft für Vermögensverwertung (Q107150954), Deutsche Bank Trust Company Americas (Q110016607)
SHA-256 83f2d7a6d9fd69b17888548db140446f6c1a9cf8b86ad6ac98b4f865cf85694f
ev_021 A-1
Source rdap_domain · Captured
NUMIS.COM — Registrar Network Solutions LLC (IANA 2) — Registered 1996-01-02 — Expires 2032-01-01 — Status client transfer prohibited — NS5/NS6.WORLDNIC.COM — DNSSEC false
SHA-256 e06f316627c361ba06b9235d1cec7c5d9264fd14925393aa032a82223e00ce77
ev_022 A-1
Source gleif_record · Captured
LEI 529900PLMCWKG4WW7813 — Deutsche Cayman Ltd. — c/o INTERTRUST CORPORATE SERVICES (CAYMAN) LIMITED, One Nexus Way, Camana Bay, George Town, Grand Cayman KY1-9005 — Cayman company 64883 — Created 1996-03-11 — Status ACTIVE but LEI LAPSED 2024-01-15 — S&P 228698026
SHA-256 1341defbd6b37ec6c273d079a87779cda53d61802aca4c1c94602a2c4b079e3f
ev_023 A-2
Source nominatim_search · Captured
Taunusanlage 12, 60325 Frankfurt am Main — Resolved to 'Deutsche-Bank-Hochhaus' (Q701538) at 50.1137472, 8.6679963 — Deutsche Bank Twin Towers, built 1984, 22m height, glass mirror building. Wikipedia de:Deutsche-Bank-Hochhaus
SHA-256 87a1563699de95872d4ebb7ee20ba856bba8008b5d0f736e6db64917c22e3278
ev_024 A-2
Source nominatim_search · Captured
Mainzer Landstraße 11-17, 60329 Frankfurt am Main — Resolved to 'Deutsche Bank Campus' at 50.1118044, 8.6670655 — 8-level glass office building, opened 2016-09-01. DWS Group HQ.
SHA-256 d8231a3fab05b6c2c72dddb0ef356470b4a388c828d17bbd6861b617a70adc52
ev_025 A-2
Source nominatim_search · Captured
Alfred-Herrhausen-Allee 16-24, 65760 Eschborn — Resolved to 'Technisches Zentrum Eschborn' (Q15131932, TZE) at 50.1325711, 8.5744123 — DB's technical center campus
SHA-256 d7e558050d2df93170367a57d44571f37623711f493daf7faa604aa4344bbc36
ev_026 A-2
Source nominatim_search · Captured
1 Columbus Circle, New York NY 10019 — Resolved to 40.7674614, -73.9818911 — Manhattan; per SEC EDGAR mailing address: DEUTSCHE BANK AG LEGAL DEPARTMENT 1 COLUMBUS CIRCLE 19TH FLOOR
SHA-256 6fb4f3834ff08854778891cca791d3ab1de5fe86b8144c7ba113247f6f718bd5
ev_027 A-2
Source nominatim_search · Captured
21 Moorfields, London EC2Y 9AG — Resolved to '21 Moorfields' building at 51.5184022, -0.0895974 — opened 2021-07-05, DB UK HQ in Broadgate/Moorgate City of London
SHA-256 c5874d5035a064b4cbe2c9b14ffdbcfb51c843ad0d9c9224b7774b2c4b5ec930
ev_028 B-2
Source hudsonrock_domain · Captured
Hudson Rock Cavalier db.com — 4,771 infostealer-infected sessions touching db.com. 344 employees (corp). 3,941 customers. 486 third-parties. Top exposed employee endpoints: ua.intranet.db.com/Citrix/RASweb (81 sessions); sg-kch5.dbrasweb.db.com/Citrix/RASweb/,DanaInfo=ua.intranet.db.com,SSL+ (51); sg-dsj5.dbrasweb.db.com/Citrix/RASweb/,DanaInfo=ua.intranet.db.com,SSL+ (47); sg-kch4.dbrasweb.db.com (36); sg-kch4.dbrasweb.db.com/Citrix/RASweb/,DanaInfo=ua.intranet.db.com,SSL+ (35). dbrasweb.db....
SHA-256 9b810eed386cd9a3d58e5f596ed3c1b3113c5d5dc3271a8123cf38da9927cd87
ev_029 A-2
Source urlscan_search · Captured
URLScan 7,507 historical scans for db.com. Surfaced services: login.isso.db.com ('Deutsche Bank Authentication Gateway', sso_custom_multi_auth_flex_Logon.sso, IPs 160.83.69.14/59.68/71.24/43.68, ASN15769 DE / AS2824 US); identity.db.com (Keycloak realm 'blueport', OAuth2/OIDC); scfportal.db.com (Salesforce sledge3-fra.slb.sfdcsvc.net 85.222.140.11 AS14340); brand.db.com (Frontify 52.57.26.120 AWS eu-central-1); research.db.com (Markit On Demand AS7334 209.234.234.52); securewebmail.db.com (Ak...
SHA-256 6c8baff7a80b3f58365ee2ae4f8e8638afe0321c154efffd332198ff151bafe2
ev_030 A-1
Source rdap_domain · Captured
AUTOBAHNFX.COM — Registrar CSC Corporate Domains (IANA 299, same as db.com) — Registered 2002-08-12 — Expires 2026-08-12 — NS DNS1/DNS2.CSCDNS.NET — DNSSEC false — Redirects to login.isso.db.com (Autobahn FX trading platform)
SHA-256 86dbce05356c91549f7e215807d3199df28269622682ca97564ca222de473e52
ev_031 A-1
Source rdap_domain · Captured
NUMIS.COM RDAP confirms ownership preserved via Network Solutions registrar (Numis was acquired by Deutsche Bank in 2023 for £410M, forming basis of DB UK investment banking arm).
SHA-256 65cdc902154b7cb38884ca8ab05caa5c45f31679244420907f405e2a41608d7b
ev_032 A-1
Source rdap_domain · Captured
PALAISPOPULAIRE.COM — Registrar CSC Corporate Domains (same as db.com) — Registered 2017-08-22 (PalaisPopulaire opened September 2018 in Berlin) — Expires 2026-08-22 — DNS1/2.CSCDNS.NET
SHA-256 c72afe3df8a9648fe74f6bbc049b981915cbe591b8e302c79900cc2bb733a757
ev_033 A-2
Source github_repo_search · Captured
GitHub org 'deutschebank' — 5 public repos: coding-exercises (Java, 16★), deutsche-bank-api-program (Java, 11★, official API tutorials), backstage-plugins (TypeScript, 8★, ARCHIVED), dbMango (C#, 3★), dbcore (ARCHIVED 2018). GitHub org 'dwsgroup' has 1 repo (CARLOS, abandoned). Code search 'org:deutschebank language:Java' returns 11 files from api-program tutorials and coding-exercises — no leaked credentials visible in indexed code.
SHA-256 68638422ba308ec907005adf85b96722f169b16bdf356d02fdc55ee9707819bc
ev_034 C-2
Source hunter_domain_search · Captured
Hunter.io db.com — 21,553 emails indexed. Pattern first.last at db.com (99% confidence). disposable: false, accept_all: false, webmail: false. Sample verified employees (LinkedIn-sourced, validated 2026-05): aveksha.joshi (AVP Operations), pratibha.yadav (AVP), ann-katrin.liewig (Auditor AVP), olumide.adisa (AVP Inst. Cash & Trade Finance), hyesi.jun (Head Liquidity Solutions US), fardad.samei (Werkstudent Chief Sustainability Office), emily.etchberger (MD CFO TDI Deputy Infrastructure CFO), ...
SHA-256 ceb5b96f811a98f23229db0c8e65f3bfec912a9080660dbd93974dd3e09821c5
ev_035 B-2
Source hudsonrock_email · Captured
robert.pettinato@db.com — 'This email address is not associated with a computer infected by an info-stealer.' Total corporate services exposed: 0. Individual MD-level account not in current stealer corpus.
SHA-256 1e0b84bc78e91c736faff338df1df4de5f8c9c9f33123c4b2497b683ea908741
ev_036 A-1
Source sec_company_concept · Captured
DEUTSCHE BANK AKTIENGESELLSCHAFT CIK 0001159508 ifrs-full:Assets EUR time-series: 2015-12-31 EUR 1,629.1B; 2016 EUR 1,590.5B; 2017 EUR 1,474.7B; 2018 EUR 1,348.1B; 2019 EUR 1,297.7B; 2020 EUR 1,325.0B; 2021 EUR 1,324.7B; 2022 EUR 1,344.2B; 2023 EUR 1,317.3B; 2024 EUR 1,391.0B; 2025-06-30 EUR 1,401.6B; 2025-12-31 EUR 1,440.0B (per 2026 20-F filing).
SHA-256 5a1c0f54a6a574a61f38d15e363b5064d0ecdc6a82be5b1f593ad5655b74228e
ev_037 B-2
Source serper_search · Captured
Serper search confirms CIK 0001159508. SEC mailing address: DEUTSCHE BANK AG - LEGAL DEPARTMENT, 1 COLUMBUS CIRCLE, 19TH FLOOR, New York NY. London Branch per filings: Deutsche Bank AG, London Branch, 21 Moorfields, London EC2Y 9DB. 2025 Form 20-F filed.
SHA-256 86efee6c6bf9c22f4ba7b7390302243f88b07b4b4508967a776d44aaac23abcc
ev_038 F-6
Source opensanctions_search · Captured
TOOL GAP — Three attempts (Wave 1, Wave 2, Wave 3) all failed with 'fetch failed' — upstream OpenSanctions service degraded throughout the investigation window. Manual cross-reference: Deutsche Bank AG is NOT on any major sanctions list (OFAC/SDN, EU, UK HMT, UN). DB has had multiple historical regulatory enforcement actions (NOT sanctions): 2017 NYDFS USD 425M for USD 10B Russian mirror-trade money laundering, 2015 USD 2.5B Libor settlement, 2017 DoJ USD 7.2B RMBS settlement, 2023 ECB on-sit...
SHA-256 29d65b646f6b13e8edc1064c210335c437edf39f000a5a55e028fd62228506a2
ev_039 A-2
Source wayback_cdx_search · Captured
Wayback Machine — earliest db.com snapshot: 1996-11-02T02:18:41Z (pre-formal-registration); domain RDAP registered 1997-09-02. Continuous capture through 2026. CDX corpus is heavily polluted with bot-spam percent-encoded crawl noise.
SHA-256 267a9baa67eeca1024b42dd3de5de7bd823b7708c42123e5ac5203d41af5d7b7
ev_040 A-1
Source cisa_kev_lookup · Captured
CISA KEV CVE-2024-3094 (XZ-utils backdoor): 0 matches in KEV catalog as of 2026-05-26. Probe confirmed KEV API operational.
SHA-256 822c7f39928bf24c5f913a142ac13106eabbda2ce37330558dccd15d33a5fbac